Atlas / MCP servers / thinkwatchproject / ThinkWatch

ThinkWatchBLOCK

mcp/thinkwatchproject/thinkwatch

Enterprise AI bastion host for secure AI API and MCP access, with unified proxying, RBAC, audit logs, rate limiting, and cost tracking across OpenAI, Anthropic, Gemini, and self-hosted LLMs.

Verdict
BLOCK
Grade
F
Trust score
54 /100
Exposed tools
2 2r · 0w · 0d
Transport
streamable-http
License
NOASSERTION
Stars
814
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

English | 中文

The enterprise-grade secure gateway for AI. Secure, audit, and govern every AI API call and MCP tool invocation across your organization — from a single control plane.

Just as an SSH secure gateway is the single gateway through which all server access must flow, ThinkWatch is the single gateway through which all AI access must flow. Every model request. Every tool call. Every token. Authenticated, authorized, rate-limited, logged, and accounted for.

┌──────────────────────────────────────┐
Claude Code ──────>│                                      │──> OpenAI
Cursor ───────────>│    Gateway  :3000                    │──> Anthropic
Custom Agent ─────>│    AI API + MCP Unified Proxy        │──> Google Gemini
CI/CD Pipeline ───>│                                      │──> Azure OpenAI / AWS Bedrock
└──────────────────────────────────────┘
┌──────────────────────────────────────┐
Admin Browser ────>│    Console  :3001                    │
│    Management UI + Admin 
Read from source at commit 5b4918d113f7OBSERVED · 2026-09-26
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add web --env PW_ADMIN_PASSWORD=${PW_ADMIN_PASSWORD} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "web": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "PW_ADMIN_PASSWORD": "${PW_ADMIN_PASSWORD}"
      }
    }
  }
}
03

Exposed tools (2)

2 read · 0 write · 0 destructive.

ToolRiskDescription
echoreadEcho input
reversereadReverse a string
04

Trust audit

BLOCKgrade F · trust 54/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (18 observation(s))
Shell
declared (2 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
crates/common/src/limits/budget.rs:225
let new_total: Result<i64, _> = fred::interfaces::LuaInterface::eval(
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
crates/server/src/handlers/auth.rs:856
let decay_result: Result<i64, _> = fred::interfaces::LuaInterface::eval(
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
crates/common/src/validation.rs:183
"169.254.169.254",
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
crates/common/src/validation.rs:185
"metadata.google.internal",
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
crates/common/src/validation.rs:379
assert!(validate_url("http://metadata.google.internal./x").is_err());
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
crates/common/src/validation.rs:387
assert!(validate_url("http://169.254.169.254/metadata").is_err());
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
crates/gateway/src/bedrock/sigv4.rs:44
const IMDS: &str = "http://169.254.169.254";
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
Makefile:203
#   TEST_DATABASE_BASE_URL=postgres://user:pwd@host:5432 \
HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
crates/test-support/src/pg.rs:25
/// `postgres://user:pwd@localhost:5432`.
HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
deploy/helm/think-watch/values-production.yaml.example:43
externalUrl: "postgres://thinkwatch:[email protected]:5432/think_watch?sslmode=require"
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
web/scripts/check-i18n.mjs:58
'settings.toolInspection.rules.${_}.name': ['curl-pipe-sh', 'base64-decode-exec', 'exfil-env', 'exfil-credentials', 'exfil-credentials-reversed', 'ssh-key-read', 'write-startup-item', 'crontab-install
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
web/scripts/check-i18n.mjs:59
'settings.toolInspection.rules.${_}.why': ['curl-pipe-sh', 'base64-decode-exec', 'exfil-env', 'exfil-credentials', 'exfil-credentials-reversed', 'ssh-key-read', 'write-startup-item', 'crontab-install'
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
crates/common/src/validation.rs:384
assert!(validate_url("http://127.0.0.1:8080").is_err());
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
crates/common/src/validation.rs:386
assert!(validate_url("http://0.0.0.0").is_err());
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
crates/common/src/validation.rs:387
assert!(validate_url("http://169.254.169.254/metadata").is_err());
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
crates/common/src/validation.rs:389
assert!(validate_url("http://10.0.0.1").is_err());
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
crates/common/src/validation.rs:390
assert!(validate_url("http://192.168.1.1").is_err());
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
crates/common/src/validation.rs:302
assert!(validate_email("Σ[email protected]").is_err());
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
.github/workflows/ci.yml:43
DATABASE_URL: postgres://postgres:postgres@localhost:5432/think_watch_test
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
.github/workflows/ci.yml:135
TEST_DATABASE_BASE_URL: postgres://postgres:postgres@localhost:5432
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
crates/auth/src/password.rs:42
let password = "correct-horse-battery-staple";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
crates/test-support/tests/encryption_roundtrip.rs:39
let secret = "oidc_super_secret_4tw";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
crates/test-support/tests/webhook_signature.rs:256
let secret = "outbox-replay-secret";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
web/src/routes/guide.tsx:286
api_key="tw-your-api-key-here",
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
web/src/routes/guide.tsx:322
api_key="tw-your-api-key-here",

Gates applied: no_behavioural_pass.

Audited 2026-09-26 · audit v0.4.1 · source sha 5b4918d113f7full audit observations/trust-audit/mcp-server/thinkwatchproject__thinkwatch.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-265b4918d113f7BLOCKF54first audit
06

Questions

What is the ThinkWatch MCP server?

Enterprise AI bastion host for secure AI API and MCP access, with unified proxying, RBAC, audit logs, rate limiting, and cost tracking across OpenAI, Anthropic, Gemini, and self-hosted LLMs.

What tools does ThinkWatch expose?

2 in total: 2 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is ThinkWatch safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (54/100) and found 10 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does ThinkWatch need?

It reads PW_ADMIN_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does ThinkWatch run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as web at 2.0.0.

How current is this page?

The grade is for one exact copy of the source (5b4918d113f7), read on 2026-09-26. The repository is watched and re-audited when it changes.

Advertisement