Watch Skill runs on your own machine — the client starts it, so there is no endpoint to ping. 699 installs a week from pypi. Last commit 8 Sep 2026.
Watch video and live sessions, keep timestamped evidence, and verify an agent's own work.
We read the source, 10 h ago · rules 3dff92dd89df
A value the model can set ends up inside a file or shell call. That is not a flaw by itself — for a terminal server it is the job — but it is where things go wrong when it is not.
result = subprocess.run(
What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.
result = subprocess.run(
cmd, shell=True, capture_output=True, text=True,
const result = spawnSync(command, [...args], {
Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.
That is not a flaw by itself — but it is where things go wrong when it is not the job. We re-read this code on every release. Watch it and you hear from us the day another one appears.
This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.
claude mcp add watch-skill -- uvx watch-skill
{
"mcpServers": {
"watch-skill": {
"args": [
"watch-skill"
],
"command": "uvx"
}
}
}
[mcp_servers.watch-skill]
command = "uvx"
args = ["watch-skill"]
{
"mcpServers": {
"watch-skill": {
"args": [
"watch-skill"
],
"command": "uvx"
}
}
}
{
"mcpServers": {
"watch-skill": {
"args": [
"watch-skill"
],
"command": "uvx"
}
}
}
Attest agent decisions and verify records on a public ledger. Evidence, not just data.
Verifiable cognition: prove a session ledger is tamper-evident; audit & import any agent's logs.
Verified open AI artifact search, trust evidence, downloads, and agent workflows from Hugging Bay.
Agent leases, signed receipts, watchdogs, and optional paid source-verification evidence.
Issue & verify signed (ed25519), hash-chained, timestamped provenance receipts for agent actions.
Stamp, upgrade, and verify Bitcoin timestamps via AI agents. No API keys required.
Verify a source or provider before an AI agent trusts it. Evidence only; unknown stays unknown.
Verify that an agent's claimed outcome actually happened, using independently gathered evidence
Answers built from our own checks of this server.