AgentWatch
Read-only watchtower for AI agents on-chain: decoded receipts, plan vs execution, Safe audits.
Should I use this
Quality & Safety
Based on automated analysis of tool definitions and protocol compliance.
Context Cost
This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.
Install
One-Click Install
Add this to your `claude_desktop_config.json` file:
{
"mcpServers": {
"agentwatch": {
"url": "https://agentwatch.agentwatch.workers.dev/mcp"
}
}
}Remote endpoints
https://agentwatch.agentwatch.workers.dev/mcpstreamable-httpWhat it can do
Tool inventory
Tools (21)
π‘list_watched
List watched addresses for this connector principal. NEW USERS: if empty, call watch_demo_set next (do not invent a global feed), then get_dashboard.
Input Schema
{
"type": "object",
"properties": {},
"additionalProperties": false
}π’get_feed(address, since)
Decoded activity feed for an address. Use when reviewing what an agent did on-chain.
Input Schema
{
"type": "object",
"properties": {
"address": {
"type": "string",
"description": "Watched address (0xβ¦40 hex)"
},
"since": {
"type": "number",
"description": "Unix seconds lower bound"
}
},
"required": [
"address"
]
}βͺrun_audit(address, chain, agents)
Run provenance audit on a Safe/address. Use when the user asks 'is this fake?' or wants a shareable verdict.
Input Schema
{
"type": "object",
"properties": {
"address": {
"type": "string",
"description": "Safe/address to audit (0xβ¦40 hex)"
},
"chain": {
"type": "string",
"enum": [
"base",
"ethereum"
]
},
"agents": {
"type": "string",
"description": "Comma-separated agent keys"
}
},
"required": [
"address"
]
}π’get_capabilities(agent_key)
Blast-radius / historical capability for an agent key. Use before trusting an agent with funds.
Input Schema
{
"type": "object",
"properties": {
"agent_key": {
"type": "string"
}
},
"required": [
"agent_key"
]
}π‘get_alerts(status)
List alerts scoped to this principal's watched addresses (empty watch list β call watch_demo_set first). Use when checking what needs attention.
Input Schema
{
"type": "object",
"properties": {
"status": {
"type": "string"
}
}
}π’get_pending_proposals(safe, chains)
Pending Safe multisig proposals from the Safe Transaction Service (indexer confidence). Pass safe=0x⦠or omit to scan all watched addresses.
Input Schema
{
"type": "object",
"properties": {
"safe": {
"type": "string",
"description": "Optional Safe address; default = all watched"
},
"chains": {
"type": "string",
"description": "Optional comma-separated chain ids"
}
}
}π’get_fidelity(agent_key)
Intentβexecution fidelity score for an agent or Safe. Use for accountability / coverage meter. Check matched_agent β false means the address has no indexed activity (as signer or as the Safe that executed), so the score is vacuous.
Input Schema
{
"type": "object",
"properties": {
"agent_key": {
"type": "string",
"description": "Agent EOA address (0xβ¦40 hex)"
}
},
"required": [
"agent_key"
]
}π’get_leaderboard(agent_key, limit)
Public standings for agents with a published passport, ranked from receipts (declared-first coverage, fidelity, reliability, hygiene, sustained work). Pass agent_key to get that agent's own rank, its component scores, and what it would need to climb. Read-only: nothing here can be self-reported.
Input Schema
{
"type": "object",
"properties": {
"agent_key": {
"type": "string",
"description": "Optional: address to locate in the standings"
},
"limit": {
"type": "number",
"description": "How many ranked rows to return (default 10, max 50)"
}
}
}π’get_benchmark(agent_key)
Counterfactual P&L / agent alpha vs do-nothing baselines. Use for performance honesty checks. Check matched_agent β false means the key has no indexed activity.
Input Schema
{
"type": "object",
"properties": {
"agent_key": {
"type": "string",
"description": "Agent EOA address (0xβ¦40 hex)"
}
},
"required": [
"agent_key"
]
}π’get_tca(event_id)
TCA market-context snapshot for an event_id (chain:txHash). Use when judging execution quality.
Input Schema
{
"type": "object",
"properties": {
"event_id": {
"type": "string"
}
},
"required": [
"event_id"
]
}βͺregister_intent(agent_key, description, declared_at, deadline_minutes, expected)
Declare an intent BEFORE broadcasting. Returns {intent_id, pairing_code}. Append the 16-hex pairing_code as the last 8 bytes of calldata (no magic prefix), then broadcast β EXCEPT bare ETH transfers to contracts (empty data + value>0): appending reverts on Safe/fallback handlers; register without a suffix and use expected.steps for multi-leg flows (e.g. approve+supply). Pairing codes are single-use and only consumed by successful (non-reverted) txs. Use deadline_minutes (relative) β normalized to absolute constraints.deadline at registration.
Input Schema
{
"type": "object",
"properties": {
"agent_key": {
"type": "string"
},
"description": {
"type": "string"
},
"declared_at": {
"type": "number"
},
"deadline_minutes": {
"type": "number",
"description": "Relative window; stored as absolute constraints.deadline"
},
"expected": {
"type": "object",
"description": "Structured shape. Use steps: ['approve','other'] (or similar) so one intent covers approve+supply/swap companions."
}
},
"required": [
"agent_key",
"description"
]
}π‘add_watch(address, chains, label)
Start watching an address. Use when onboarding a new agent or Safe.
Input Schema
{
"type": "object",
"properties": {
"address": {
"type": "string",
"description": "Address to watch (0xβ¦40 hex)"
},
"chains": {
"type": "string"
},
"label": {
"type": "string",
"description": "Optional short label (e.g. Agent EOA)"
}
},
"required": [
"address"
]
}π‘watch_demo_set
ONE-SHOT cold-start for brand-new Claude / MCP users with an empty watch list. Adds the July 18 fixture (Agent EOA + Safe A + Safe B on Base, with declared intents) and one live Polygon trading bot, so the first dashboard has recent activity. Call this FIRST after connect when list_watched is empty, then call get_dashboard (Always allow the App). Idempotent β skips addresses already watched.
Input Schema
{
"type": "object",
"properties": {},
"additionalProperties": false
}π‘refresh_watches(address, chains)
Force an immediate poller pass over this principal's watched addresses (catch up txs from explorers into AgentWatch). Use after add_watch / a fresh broadcast when get_feed is still empty. Optional address / chains to focus the pass.
Input Schema
{
"type": "object",
"properties": {
"address": {
"type": "string",
"description": "Optional single address to refresh (0xβ¦40 hex)"
},
"chains": {
"type": "string",
"description": "Optional csv of chains (default: ethereum,base first, then the rest)"
}
}
}π’get_agent_passport(address)
Read the declared identity of a watched agent (name, model provider, how often it runs, role, purpose, operator) and whether its public passport page is published.
Input Schema
{
"type": "object",
"properties": {
"address": {
"type": "string",
"description": "Watched agent address (0xβ¦40 hex)"
}
},
"required": [
"address"
]
}π‘set_agent_passport(address, display_name, provider, model, cadence, ...)
Declare who a watched agent is: model provider, run cadence, role, purpose, operator, and whether to publish a shareable public passport at /a/<slug>. Declarations never change the receipt-derived numbers next to them; publishing exposes only this address, never the rest of the watch list.
Input Schema
{
"type": "object",
"properties": {
"address": {
"type": "string",
"description": "Watched agent address (0xβ¦40 hex)"
},
"display_name": {
"type": "string",
"description": "Name shown instead of the raw address"
},
"provider": {
"type": "string",
"enum": [
"anthropic",
"openai",
"google",
"xai",
"meta",
"mistral",
"deepseek",
"qwen",
"open_source",
"multi",
"none",
"unknown"
],
"description": "Which model drives the agent"
},
"model": {
"type": "string",
"description": "Optional model or framework detail"
},
"cadence": {
"type": "string",
"enum": [
"always_on",
"scheduled",
"event_driven",
"on_demand",
"unknown"
],
"description": "always_on, scheduled, event_driven, on_demand"
},
"role": {
"type": "string",
"enum": [
"trading",
"market_making",
"prediction",
"treasury",
"payments",
"research",
"infra",
"personal",
"other"
]
},
"purpose": {
"type": "string",
"description": "One or two sentences on what it is for"
},
"operator": {
"type": "string",
"description": "Who runs it"
},
"public": {
"type": "boolean",
"description": "Publish a public passport page"
}
},
"required": [
"address"
]
}π’list_recovery_owners
List this user's saved recovery wallets (human co-signers for default 1/2 Safes). Each may have a label/purpose β users often keep several for different vaults.
Input Schema
{
"type": "object",
"properties": {},
"additionalProperties": false
}π‘set_recovery_owner(address, label, purpose, make_default)
Save or update a recovery address for this user. Product default Safe is then 1/2: threshold 1, owners = [agent, this recovery]. Use make_default=true to prefer this label in get_safe_defaults.
Input Schema
{
"type": "object",
"properties": {
"address": {
"type": "string",
"description": "0x recovery wallet the human controls"
},
"label": {
"type": "string",
"description": "Short name, e.g. hardware, treasury, personal"
},
"purpose": {
"type": "string",
"description": "What this recovery is for, e.g. default, trading"
},
"make_default": {
"type": "boolean",
"description": "Prefer this label for default Safes"
}
},
"required": [
"address"
]
}π΄remove_recovery_owner(address)
Remove a saved recovery address for this user.
Input Schema
{
"type": "object",
"properties": {
"address": {
"type": "string"
}
},
"required": [
"address"
]
}π’get_safe_defaults(agent_key, recovery_label, purpose, chain, all_recoveries)
Return the default Safe ownership plan for an agent EOA: threshold 1 + agent + selected recovery (1/2 when one recovery is set). Call before register_intent for Safe deploys. AgentWatch never deploys or signs.
Input Schema
{
"type": "object",
"properties": {
"agent_key": {
"type": "string",
"description": "Agent EOA that will be an owner/signer"
},
"recovery_label": {
"type": "string",
"description": "Optional label to pick among several recoveries"
},
"purpose": {
"type": "string",
"description": "Optional purpose filter (e.g. trading)"
},
"chain": {
"type": "string",
"description": "Optional chain hint for the intent constraints"
},
"all_recoveries": {
"type": "boolean",
"description": "If true, include all matching recoveries (1/n) instead of just the default one"
}
},
"required": [
"agent_key"
]
}π‘get_dashboard(persona)
Persona-tailored dashboard brief (fidelity, alerts, pending plans, recent planned-vs-executed). NEW USERS with empty watches: call watch_demo_set first, then get_dashboard again. Narrate in plain language; ask the user to Always allow the AgentWatch MCP App widget when the host prompts.
Input Schema
{
"type": "object",
"properties": {
"persona": {
"type": "string",
"description": "Optional override; otherwise uses saved persona"
}
}
}Community
Evidence