Skip to main content
Glama
derkcc

watchcheck

by derkcc

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault

No arguments

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": false
}
prompts
{
  "listChanged": false
}
resources
{
  "subscribe": false,
  "listChanged": false
}
experimental
{}

Tools

Functions exposed to the LLM to take actions

NameDescription
scanA

Scan this Mac (read-only) and report identified monitoring software.

Inspects running processes, launchd jobs, system/kernel extensions, MDM enrollment and trusted certificates, then matches them against the watchcheck signature database. Returns identified EDR/DLP/MDM/network-audit software with evidence, capabilities and privacy impact. Group the result by category and explain each finding in plain language for the user.

explain_processA

Explain one process / launchd label / bundle id in plain language.

Built for non-technical users who paste a single name from Activity Monitor (e.g. "WindowServer", "EasyConnect", "GoogleSoftwareUpdate"). Resolution order: monitoring signature → common benign catalog → returns unknown so the host LLM can explain the long tail. Always answers something useful.

overviewA

Friendly typed overview of EVERYTHING running on this Mac (read-only).

For users who don't understand processes: classifies every running process into types (Apple system / browser / cloud-sync / updater / communication / your own VPN / monitoring / unknown ...), collapses duplicates (e.g. 30 Chrome helpers -> 1), and flags monitoring software. Present the type counts first, reassure that most are normal, then call out anything flagged.

list_signaturesA

List everything watchcheck can currently identify (transparency).

Returns the signature catalog (vendor, product, category, origin, coverage) without the raw match tokens. Use this to tell the user what the tool knows — and what gaps remain (especially Chinese enterprise tools).

raw_inventoryA

Return the raw read-only inventory with NO matching (power users).

Dumps processes, launchd jobs, extensions, kexts, certs and MDM status as collected. Use this to investigate something watchcheck didn't recognize, or to gather artifacts for a new signature contribution.

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription

No resources

TDQS

A4.4/5.0

Scored across 5 tools

Disambiguation5/5

Each tool has a distinct purpose: explain_process explains a single process, list_signatures shows the catalog, overview gives a high-level summary, raw_inventory provides raw data for power users, and scan performs a full monitoring detection. No overlap.

Naming Consistency3/5

Tool names use snake_case but mix conventions: verb_noun (explain_process, list_signatures), single word (overview, scan), and noun phrase (raw_inventory). While readable, the pattern is inconsistent.

Tool Count5/5

Five tools is well-scoped for the server's purpose of monitoring software detection. Each tool serves a clear role without redundancy, fitting within the ideal 3-15 range.

Completeness4/5

The tool set covers the core workflow of scanning, explaining, and listing known signatures. A minor gap exists in advanced features like diffing scans, but the domain is well-covered for transparency and detection.

Maintenance

ActivityInactive
ResponsivenessNo issues