ThinkWatchBLOCK
Enterprise AI bastion host for secure AI API and MCP access, with unified proxying, RBAC, audit logs, rate limiting, and cost tracking across OpenAI, Anthropic, Gemini, and self-hosted LLMs.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
English | 中文
The enterprise-grade secure gateway for AI. Secure, audit, and govern every AI API call and MCP tool invocation across your organization — from a single control plane.
Just as an SSH secure gateway is the single gateway through which all server access must flow, ThinkWatch is the single gateway through which all AI access must flow. Every model request. Every tool call. Every token. Authenticated, authorized, rate-limited, logged, and accounted for.
┌──────────────────────────────────────┐ Claude Code ──────>│ │──> OpenAI Cursor ───────────>│ Gateway :3000 │──> Anthropic Custom Agent ─────>│ AI API + MCP Unified Proxy │──> Google Gemini CI/CD Pipeline ───>│ │──> Azure OpenAI / AWS Bedrock └──────────────────────────────────────┘ ┌──────────────────────────────────────┐ Admin Browser ────>│ Console :3001 │ │ Management UI + Admin
5b4918d113f7OBSERVED · 2026-09-26Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add web --env PW_ADMIN_PASSWORD=${PW_ADMIN_PASSWORD} -- npx -y [email protected]{
"mcpServers": {
"web": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"PW_ADMIN_PASSWORD": "${PW_ADMIN_PASSWORD}"
}
}
}
}Exposed tools (2)
2 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
echo | read | Echo input |
reverse | read | Reverse a string |
Trust audit
BLOCKgrade F · trust 54/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- declared (18 observation(s))
- Shell
- declared (2 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
let new_total: Result<i64, _> = fred::interfaces::LuaInterface::eval(
let decay_result: Result<i64, _> = fred::interfaces::LuaInterface::eval(
"169.254.169.254",
"metadata.google.internal",
assert!(validate_url("http://metadata.google.internal./x").is_err());assert!(validate_url("http://169.254.169.254/metadata").is_err());const IMDS: &str = "http://169.254.169.254";
# TEST_DATABASE_BASE_URL=postgres://user:pwd@host:5432 \
/// `postgres://user:pwd@localhost:5432`.
externalUrl: "postgres://thinkwatch:[email protected]:5432/think_watch?sslmode=require"
'settings.toolInspection.rules.${_}.name': ['curl-pipe-sh', 'base64-decode-exec', 'exfil-env', 'exfil-credentials', 'exfil-credentials-reversed', 'ssh-key-read', 'write-startup-item', 'crontab-install'settings.toolInspection.rules.${_}.why': ['curl-pipe-sh', 'base64-decode-exec', 'exfil-env', 'exfil-credentials', 'exfil-credentials-reversed', 'ssh-key-read', 'write-startup-item', 'crontab-install'assert!(validate_url("http://127.0.0.1:8080").is_err());assert!(validate_url("http://0.0.0.0").is_err());assert!(validate_url("http://169.254.169.254/metadata").is_err());assert!(validate_url("http://10.0.0.1").is_err());assert!(validate_url("http://192.168.1.1").is_err());assert!(validate_email("Σ[email protected]").is_err());DATABASE_URL: postgres://postgres:postgres@localhost:5432/think_watch_test
TEST_DATABASE_BASE_URL: postgres://postgres:postgres@localhost:5432
let password = "correct-horse-battery-staple";
let secret = "oidc_super_secret_4tw";
let secret = "outbox-replay-secret";
api_key="tw-your-api-key-here",
api_key="tw-your-api-key-here",
Gates applied: no_behavioural_pass.
5b4918d113f7full audit observations/trust-audit/mcp-server/thinkwatchproject__thinkwatch.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-26 | 5b4918d113f7 | BLOCK | F | 54 | first audit |
Questions
What is the ThinkWatch MCP server?
Enterprise AI bastion host for secure AI API and MCP access, with unified proxying, RBAC, audit logs, rate limiting, and cost tracking across OpenAI, Anthropic, Gemini, and self-hosted LLMs.
What tools does ThinkWatch expose?
2 in total: 2 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is ThinkWatch safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (54/100) and found 10 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does ThinkWatch need?
It reads PW_ADMIN_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does ThinkWatch run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as web at 2.0.0.
How current is this page?
The grade is for one exact copy of the source (5b4918d113f7), read on 2026-09-26. The repository is watched and re-audited when it changes.