watchcheck
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| scanA | Scan this Mac (read-only) and report identified monitoring software. Inspects running processes, launchd jobs, system/kernel extensions, MDM enrollment and trusted certificates, then matches them against the watchcheck signature database. Returns identified EDR/DLP/MDM/network-audit software with evidence, capabilities and privacy impact. Group the result by category and explain each finding in plain language for the user. |
| explain_processA | Explain one process / launchd label / bundle id in plain language. Built for non-technical users who paste a single name from Activity Monitor
(e.g. "WindowServer", "EasyConnect", "GoogleSoftwareUpdate"). Resolution order:
monitoring signature → common benign catalog → returns |
| overviewA | Friendly typed overview of EVERYTHING running on this Mac (read-only). For users who don't understand processes: classifies every running process into types (Apple system / browser / cloud-sync / updater / communication / your own VPN / monitoring / unknown ...), collapses duplicates (e.g. 30 Chrome helpers -> 1), and flags monitoring software. Present the type counts first, reassure that most are normal, then call out anything flagged. |
| list_signaturesA | List everything watchcheck can currently identify (transparency). Returns the signature catalog (vendor, product, category, origin, coverage) without the raw match tokens. Use this to tell the user what the tool knows — and what gaps remain (especially Chinese enterprise tools). |
| raw_inventoryA | Return the raw read-only inventory with NO matching (power users). Dumps processes, launchd jobs, extensions, kexts, certs and MDM status as collected. Use this to investigate something watchcheck didn't recognize, or to gather artifacts for a new signature contribution. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 5 tools
Each tool has a distinct purpose: explain_process explains a single process, list_signatures shows the catalog, overview gives a high-level summary, raw_inventory provides raw data for power users, and scan performs a full monitoring detection. No overlap.
Tool names use snake_case but mix conventions: verb_noun (explain_process, list_signatures), single word (overview, scan), and noun phrase (raw_inventory). While readable, the pattern is inconsistent.
Five tools is well-scoped for the server's purpose of monitoring software detection. Each tool serves a clear role without redundancy, fitting within the ideal 3-15 range.
The tool set covers the core workflow of scanning, explaining, and listing known signatures. A minor gap exists in advanced features like diffing scans, but the domain is well-covered for transparency and detection.