Watchdog
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| WATCHDOG_BUDGET_USD | No | Refuse payments beyond this total, per server process. | 5 |
| WATCHDOG_SOLANA_RPC_URL | No | RPC URL used to build Solana payments. | public mainnet |
| WATCHDOG_EVM_PRIVATE_KEY | No | Base wallet private key, hex. Optional; without a key for a chain, its tools return the price and how to pay instead of an answer. | none |
| WATCHDOG_MAX_PER_CALL_USD | No | Refuse any single payment above this amount. | 1 |
| WATCHDOG_SOLANA_PRIVATE_KEY | No | Solana wallet private key, base58 (as Phantom exports it). Optional; without a key for a chain, its tools return the price and how to pay instead of an answer. | none |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| solana_program_authorityA | Use before signing a transaction for, or depositing into, a Solana mainnet program. Answers who can replace its code: immutable, a single key, a Squads v4 multisig (threshold, members and time lock read on-chain, the vault re-derived as proof), Squads v3 or SPL Governance; plus the last deploy date, OtterSec verified build, embedded security.txt and severity-ranked flags. Costs $0.05 USDC on Solana, paid over x402 from WATCHDOG_SOLANA_PRIVATE_KEY. An address that holds no program is not charged. |
| evm_contract_controlA | Use before approving a token, depositing into, or signing for a contract on Base or Robinhood Chain. Detects the proxy kind (EIP-1967 transparent, UUPS, beacon, legacy zeppelinos, EIP-1167 clone, diamond, EIP-7702), the live implementation, and follows the upgrade controller and owner to the end: one key, a Safe (threshold of owners), a timelock (delay). Sourcify verification for the address and the implementation. Costs $0.05 USDC on Base, paid over x402 from WATCHDOG_EVM_PRIVATE_KEY. An address with no code is not charged. |
| dependency_advisoriesA | Use before adding or upgrading a dependency, or to triage a lockfile. Give lockfile_path (a Cargo.lock, package-lock.json or yarn.lock on disk, read locally) or the lockfile text, or a list of up to 100 packages. Rust crates go to Solana Watchdog (RustSec/OSV), npm packages to EVM Watchdog (GitHub/OSV). Only registry packages are checked; workspace and git dependencies are skipped. Costs $0.01 USDC per call (Solana for crates, Base for npm). Settled only if the answer exists. |
| scan_repoA | Use before a release or an integration: scans a public GitHub repo for advisories on its exact pinned dependencies (split into what ships on-chain and what is tooling), build hygiene, and code leads for known bug classes with file:line. ecosystem 'solana' for Rust/Anchor programs, 'evm' for Solidity (Foundry/Hardhat). Costs $0.50 USDC (Solana or Base). Waits up to wait_seconds for the report; otherwise returns jobId and accessToken for get_scan_report. A scan, not an audit. |
| get_scan_reportA | Free. Returns the status of a scan started with scan_repo and, once done, its JSON report. |
| watch_createA | Use to be told, for 30 days, when something you rely on changes: a Solana program (programId: authority, multisig rules, code upgrade, lost verification), an EVM contract (address + chain: new implementation, controller or owner, weaker Safe or timelock), or a lockfile (lockfile_path: any new advisory). Hourly checks; each change is POSTed to your https webhook, signed with x-watchdog-signature: sha256=HMAC(secret, body). Costs $0.90 USDC for the period (Solana for programs and Cargo.lock, Base for contracts and npm lockfiles). Returns watchId, secret and accessToken, each shown once. |
| watch_statusB | Free. Lists what a watch has seen (also kept when the webhook was down), or cancels it with cancel: true. |
| watchdog_walletA | Free. Shows which payment wallets this server is configured with (addresses only), the per-call cap, the session budget, what was spent, and the price of each tool. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 8 tools
Most tools target distinct resources and actions, with clear chain-specific separation (Solana vs EVM). However, dependency_advisories and scan_repo both check dependency vulnerabilities and could be confused when an agent just needs a lockfile check, though descriptions clarify the difference.
All names use snake_case, but verb styles are mixed: some are verb_noun (get_scan_report, scan_repo, watch_create), while others are noun phrases (solana_program_authority, evm_contract_control, dependency_advisories, watchdog_wallet). The set is readable but lacks a predictable pattern.
8 tools is well-scoped for a paid blockchain security scanning and monitoring service. Each tool has a clear role, and the paired start/status tools (scan_repo/get_scan_report, watch_create/watch_status) earn their place.
Core CRUD-like lifecycle is covered for watches (create, status, cancel) and scans (start, retrieve report). Minor gaps exist: there is no way to cancel an in-progress scan or list past scans/jobs, but agents can work around these limitations.