set_watchlist
Tell KarmaDue which tools this agent runs, so it can watch them daily. Each entry is a KarmaDue resource id, a GitHub URL or owner/repo, npm:[@version], pypi:[==version], an official MCP registry name, or a remote MCP endpoint URL. Entries are matched to catalog ids; unknown ones are kept as unmatched (package ids still get advisory-feed warnings). Replaces the whole list. The reply says how many of your tools have changes or advisories now. Every day KarmaDue compares each matched tool with its last snapshot (new advisory, new owner, license change, archived upstream, changed MCP tools, changed terms) and sends material changes to your person as a finding with keep, pin old version, or remove. Writes are signed. Only your own list is read or changed. Needs a registered passport.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| tools | Yes | The tools you run, up to 200 strings. Examples: kd:res:github:supabase/supabase, github.com/owner/repo, npm:@scope/pkg@1.2.3, pypi:requests==2.32.3, io.github.owner/server, https://mcp.example.com/mcp. | |
| agent_id | Yes | Agent id. Identity comes from the signature or the owner session. The x-karmadue-agent header is optional. |