MCP server for Solana and EVM Watchdog: who can change a program or contract, dependency advisories, repo scans and watches, paid per call over x402.
- ✓Open-source license (MIT)
- ✓Actively maintained (<30d)
- ✓Clear description
- ✓Topics declared
- ✓Documented (README)
claude mcp add watchdog-mcp -- npx -y watchdog-mcp{
"mcpServers": {
"watchdog-mcp": {
"command": "npx",
"args": ["-y", "watchdog-mcp"],
"env": {
"WATCHDOG_SOLANA_PRIVATE_KEY": "<watchdog_solana_private_key>",
"WATCHDOG_EVM_PRIVATE_KEY": "<watchdog_evm_private_key>"
}
}
}
}WATCHDOG_SOLANA_PRIVATE_KEYWATCHDOG_EVM_PRIVATE_KEYMCP Servers overview
# watchdog-mcp
An MCP server for **Solana Watchdog** and **EVM Watchdog**. It gives an agent the
security checks it needs at the moment it decides: before signing for a program,
before approving a contract, before adding a dependency. Each paid call costs cents in
USDC and is paid automatically over [x402](https://x402.org), from a wallet you
provide, within limits you set.
Results are checks, not audits.
## Tools
| Tool | Use it | Price |
|---|---|---|
| `solana_program_authority` | before signing for a Solana program: who can replace its code (single key, Squads multisig with threshold and time lock, DAO, immutable), last deploy, verified build, security.txt | $0.05 (Solana) |
| `evm_contract_control` | before approving or depositing on Base / Robinhood Chain: proxy kind, live implementation, who controls upgrades and ownership (key, Safe, timelock), Sourcify verification | $0.05 (Base) |
| `dependency_advisories` | before adding a dependency: advisories for a `Cargo.lock`, `package-lock.json` or `yarn.lock` on disk, or a package list | $0.01 |
| `scan_repo` | before a release: a full scan of a public GitHub repo (Rust/Anchor or Solidity) | $0.50 |
| `get_scan_report` | status and report of a scan | free |
| `watch_create` | to be alerted for 30 days when a program, contract or lockfile changes, by signed webhook | $0.90 |
| `watch_status` | events of a watch, or cancel it | free |
| `watchdog_wallet` | which wallets are set, caps, what was spent | free |
An address that holds no program or contract is not charged. A dependency check is
settled only once its answer exists.
## Install
Claude Code:
```sh
claude mcp add watchdog \
-e WATCHDOG_SOLANA_PRIVATE_KEY=<base58 key of a Solana wallet holding a little USDC> \
-e WATCHDOG_EVM_PRIVATE_KEY=<hex key of a Base wallet holding a little USDC> \
-- npx -y watchdog-mcp
```
Claude Desktop, Cursor and other clients (`mcpServers` JSON):
```json
{
"mcpServers": {
"watchdog": {
"command": "npx",
"args": ["-y", "watchdog-mcp"],
"env": {
"WATCHDOG_SOLANA_PRIVATE_KEY": "…",
"WATCHDOG_EVM_PRIVATE_KEY": "…",
"WATCHDOG_BUDGET_USD": "5"
}
}
}
}
```
From a clone of this repository, `scripts/add-to-claude-code.sh` does the Claude Code step for you: it reads the Solana key from the clipboard, checks it without printing it, and registers the server.
Both keys are optional. Without a key for a chain, its tools return the price and how
to pay instead of an answer.
**Use a dedicated wallet** that holds only what you are willing to spend on checks.
No SOL or ETH is needed: the x402 facilitator pays the network fee.
## Configuration
| Variable | Default | |
|---|---|---|
| `WATCHDOG_SOLANA_PRIVATE_KEY` | none | Solana wallet, base58 (as Phantom exports it) |
| `WATCHDOG_EVM_PRIVATE_KEY` | none | Base wallet, hex |
| `WATCHDOG_MAX_PER_CALL_USD` | `1` | refuse any single payment above this |
| `WATCHDOG_BUDGET_USD` | `5` | refuse payments beyond this total, per server process |
| `WATCHDOG_SOLANA_RPC_URL` | public mainnet | RPC used to build Solana payments |
## What protects your wallet
Every payment is screened before anything is signed:
- it must go to the Watchdog merchant wallet of that service, in USDC, on the expected
network. A server that asked to be paid elsewhere would be refused;
- it must fit under the per-call cap and the remaining session budget;
- scan and watch access tokens are only ever sent back to the Watchdog that issued them.
Keys never appear in tool output or errors, including when a key is malformed or of
the wrong chain.
## License
MIT
What people ask about watchdog-mcp
What is OxToF/watchdog-mcp?
+
OxToF/watchdog-mcp is mcp servers for the Claude AI ecosystem. MCP server for Solana and EVM Watchdog: who can change a program or contract, dependency advisories, repo scans and watches, paid per call over x402. It has 0 GitHub stars and its last recorded update is dated 2026-10-01.
How do I install watchdog-mcp?
+
You can install watchdog-mcp by cloning the repository (https://github.com/OxToF/watchdog-mcp) or following the README instructions on GitHub. ClaudeWave also provides quick install blocks on this page.
Is OxToF/watchdog-mcp safe to use?
+
Our security agent has analyzed OxToF/watchdog-mcp and assigned a Trust Score of 95/100 (tier: Verified). See the full breakdown of passed checks and flags on this page.
Who maintains OxToF/watchdog-mcp?
+
OxToF/watchdog-mcp is maintained by OxToF. The last recorded GitHub activity is dated 2026-10-01, with 0 open issues.
Are there alternatives to watchdog-mcp?
+
Yes. On ClaudeWave you can browse similar mcp servers at /categories/mcp, sorted by popularity or recent activity.
Deploy watchdog-mcp to your cloud
Ship this repo to production in minutes. Each platform spins up its own environment with editable env vars.
Maintain this repo? Add a badge to your README
Drop the badge into your GitHub README to show it's tracked on ClaudeWave. Each badge links back to this page and reflects the live Trust Score.
[](https://claudewave.com/repo/oxtof-watchdog-mcp)<a href="https://claudewave.com/repo/oxtof-watchdog-mcp"><img src="https://claudewave.com/api/badge/oxtof-watchdog-mcp" alt="Featured on ClaudeWave: OxToF/watchdog-mcp" width="320" height="64" /></a>More MCP Servers
Fair-code workflow automation platform with native AI capabilities. Combine visual building with custom code, self-host or cloud, 400+ integrations.
User-friendly AI Interface (Supports Ollama, OpenAI API, ...)
An open-source AI agent that brings the power of Gemini directly into your terminal.
Real-time global intelligence dashboard. AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational awareness interface
🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ and follow here for daily tips and tricks: https://x.com/Scrapling_dev
The fastest path to AI-powered full stack observability, even for lean teams.