Skip to main content
Glama

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
WATCHDOG_BUDGET_USDNoRefuse payments beyond this total, per server process.5
WATCHDOG_SOLANA_RPC_URLNoRPC URL used to build Solana payments.public mainnet
WATCHDOG_EVM_PRIVATE_KEYNoBase wallet private key, hex. Optional; without a key for a chain, its tools return the price and how to pay instead of an answer.none
WATCHDOG_MAX_PER_CALL_USDNoRefuse any single payment above this amount.1
WATCHDOG_SOLANA_PRIVATE_KEYNoSolana wallet private key, base58 (as Phantom exports it). Optional; without a key for a chain, its tools return the price and how to pay instead of an answer.none

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": true
}

Tools

Functions exposed to the LLM to take actions

NameDescription
solana_program_authorityA

Use before signing a transaction for, or depositing into, a Solana mainnet program. Answers who can replace its code: immutable, a single key, a Squads v4 multisig (threshold, members and time lock read on-chain, the vault re-derived as proof), Squads v3 or SPL Governance; plus the last deploy date, OtterSec verified build, embedded security.txt and severity-ranked flags. Costs $0.05 USDC on Solana, paid over x402 from WATCHDOG_SOLANA_PRIVATE_KEY. An address that holds no program is not charged.

evm_contract_controlA

Use before approving a token, depositing into, or signing for a contract on Base or Robinhood Chain. Detects the proxy kind (EIP-1967 transparent, UUPS, beacon, legacy zeppelinos, EIP-1167 clone, diamond, EIP-7702), the live implementation, and follows the upgrade controller and owner to the end: one key, a Safe (threshold of owners), a timelock (delay). Sourcify verification for the address and the implementation. Costs $0.05 USDC on Base, paid over x402 from WATCHDOG_EVM_PRIVATE_KEY. An address with no code is not charged.

dependency_advisoriesA

Use before adding or upgrading a dependency, or to triage a lockfile. Give lockfile_path (a Cargo.lock, package-lock.json or yarn.lock on disk, read locally) or the lockfile text, or a list of up to 100 packages. Rust crates go to Solana Watchdog (RustSec/OSV), npm packages to EVM Watchdog (GitHub/OSV). Only registry packages are checked; workspace and git dependencies are skipped. Costs $0.01 USDC per call (Solana for crates, Base for npm). Settled only if the answer exists.

scan_repoA

Use before a release or an integration: scans a public GitHub repo for advisories on its exact pinned dependencies (split into what ships on-chain and what is tooling), build hygiene, and code leads for known bug classes with file:line. ecosystem 'solana' for Rust/Anchor programs, 'evm' for Solidity (Foundry/Hardhat). Costs $0.50 USDC (Solana or Base). Waits up to wait_seconds for the report; otherwise returns jobId and accessToken for get_scan_report. A scan, not an audit.

get_scan_reportA

Free. Returns the status of a scan started with scan_repo and, once done, its JSON report.

watch_createA

Use to be told, for 30 days, when something you rely on changes: a Solana program (programId: authority, multisig rules, code upgrade, lost verification), an EVM contract (address + chain: new implementation, controller or owner, weaker Safe or timelock), or a lockfile (lockfile_path: any new advisory). Hourly checks; each change is POSTed to your https webhook, signed with x-watchdog-signature: sha256=HMAC(secret, body). Costs $0.90 USDC for the period (Solana for programs and Cargo.lock, Base for contracts and npm lockfiles). Returns watchId, secret and accessToken, each shown once.

watch_statusB

Free. Lists what a watch has seen (also kept when the webhook was down), or cancels it with cancel: true.

watchdog_walletA

Free. Shows which payment wallets this server is configured with (addresses only), the per-call cap, the session budget, what was spent, and the price of each tool.

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription

No resources

TDQS

A3.9/5.0

Scored across 8 tools

Disambiguation4/5

Most tools target distinct resources and actions, with clear chain-specific separation (Solana vs EVM). However, dependency_advisories and scan_repo both check dependency vulnerabilities and could be confused when an agent just needs a lockfile check, though descriptions clarify the difference.

Naming Consistency3/5

All names use snake_case, but verb styles are mixed: some are verb_noun (get_scan_report, scan_repo, watch_create), while others are noun phrases (solana_program_authority, evm_contract_control, dependency_advisories, watchdog_wallet). The set is readable but lacks a predictable pattern.

Tool Count5/5

8 tools is well-scoped for a paid blockchain security scanning and monitoring service. Each tool has a clear role, and the paired start/status tools (scan_repo/get_scan_report, watch_create/watch_status) earn their place.

Completeness4/5

Core CRUD-like lifecycle is covered for watches (create, status, cancel) and scans (start, retrieve report). Minor gaps exist: there is no way to cancel an in-progress scan or list past scans/jobs, but agents can work around these limitations.