dev.workers.agentwatch.agentwatch/agentwatch

AgentWatch

Read-only watchtower for AI agents on-chain: decoded receipts, plan vs execution, Safe audits.

0.5.1
Version
remote
Transport
21
Tools

Security review

Review passed

Reviewed 1d ago.

  • tools: 21 tools scanned
  • metadata: scanned

No findings.

Tools (21)

  • list_watched

    List watched addresses for this connector principal. NEW USERS: if empty, call watch_demo_set next (do not invent a global feed), then get_dashboard.

  • get_feed

    Decoded activity feed for an address. Use when reviewing what an agent did on-chain.

  • run_audit

    Run provenance audit on a Safe/address. Use when the user asks 'is this fake?' or wants a shareable verdict.

  • get_capabilities

    Blast-radius / historical capability for an agent key. Use before trusting an agent with funds.

  • get_alerts

    List alerts scoped to this principal's watched addresses (empty watch list → call watch_demo_set first). Use when checking what needs attention.

  • get_pending_proposals

    Pending Safe multisig proposals from the Safe Transaction Service (indexer confidence). Pass safe=0x… or omit to scan all watched addresses.

  • get_fidelity

    Intent↔execution fidelity score for an agent or Safe. Use for accountability / coverage meter. Check matched_agent — false means the address has no indexed activity (as signer or as the Safe that executed), so the score is vacuous.

  • get_leaderboard

    Public standings for agents with a published passport, ranked from receipts (declared-first coverage, fidelity, reliability, hygiene, sustained work). Pass agent_key to get that agent's own rank, its component scores, and what it would need to climb. Read-only: nothing here can be self-reported.

  • get_benchmark

    Counterfactual P&L / agent alpha vs do-nothing baselines. Use for performance honesty checks. Check matched_agent — false means the key has no indexed activity.

  • get_tca

    TCA market-context snapshot for an event_id (chain:txHash). Use when judging execution quality.

  • register_intent

    Declare an intent BEFORE broadcasting. Returns {intent_id, pairing_code}. Append the 16-hex pairing_code as the last 8 bytes of calldata (no magic prefix), then broadcast — EXCEPT bare ETH transfers to contracts (empty data + value>0): appending reverts on Safe/fallback handlers; register without a suffix and use expected.steps for multi-leg flows (e.g. approve+supply). Pairing codes are single-use and only consumed by successful (non-reverted) txs. Use deadline_minutes (relative) — normalized to absolute constraints.deadline at registration.

  • add_watch

    Start watching an address. Use when onboarding a new agent or Safe.

  • watch_demo_set

    ONE-SHOT cold-start for brand-new Claude / MCP users with an empty watch list. Adds the July 18 fixture (Agent EOA + Safe A + Safe B on Base, with declared intents) and one live Polygon trading bot, so the first dashboard has recent activity. Call this FIRST after connect when list_watched is empty, then call get_dashboard (Always allow the App). Idempotent — skips addresses already watched.

  • refresh_watches

    Force an immediate poller pass over this principal's watched addresses (catch up txs from explorers into AgentWatch). Use after add_watch / a fresh broadcast when get_feed is still empty. Optional address / chains to focus the pass.

  • get_agent_passport

    Read the declared identity of a watched agent (name, model provider, how often it runs, role, purpose, operator) and whether its public passport page is published.

  • set_agent_passport

    Declare who a watched agent is: model provider, run cadence, role, purpose, operator, and whether to publish a shareable public passport at /a/<slug>. Declarations never change the receipt-derived numbers next to them; publishing exposes only this address, never the rest of the watch list.

  • list_recovery_owners

    List this user's saved recovery wallets (human co-signers for default 1/2 Safes). Each may have a label/purpose — users often keep several for different vaults.

  • set_recovery_owner

    Save or update a recovery address for this user. Product default Safe is then 1/2: threshold 1, owners = [agent, this recovery]. Use make_default=true to prefer this label in get_safe_defaults.

  • remove_recovery_owner

    Remove a saved recovery address for this user.

  • get_safe_defaults

    Return the default Safe ownership plan for an agent EOA: threshold 1 + agent + selected recovery (1/2 when one recovery is set). Call before register_intent for Safe deploys. AgentWatch never deploys or signs.

  • get_dashboard

    Persona-tailored dashboard brief (fidelity, alerts, pending plans, recent planned-vs-executed). NEW USERS with empty watches: call watch_demo_set first, then get_dashboard again. Narrate in plain language; ask the user to Always allow the AgentWatch MCP App widget when the host prompts.

AgentWatch MCP server · CodexGuild