gowrav-m/AgentOps Watchtower

Black box recorder, MCP safety scanner, runtime firewall, and evidence generator for AI agent workflows.

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Activelast commit May 30, 2026
License
MIT

Pinned Snippet

workflow.ymlSHA-pinned
uses: gowrav-m/agentops-watchtower@f2317b7b3bc739bde15bfd2ca887d450215764db # v1.5.0

tags can be moved; commit SHAs can't. why a SHA?

namedescriptionrequireddefault
descriptorMCP descriptor JSON path.no""
configMCP client config path.no""
traceAgent trace JSONL/Markdown path for runtime attack graph analysis.no""
serverMCP server name or inventory id for gate-mcp.no""
fail-onSeverity threshold that fails the workflow.nohigh
package-versionnpm version of agentops-watchtower to run.nolatest
run-agent-bomGenerate AgentBOM when config is provided.notrue
run-admissionRun MCP admission when config and descriptor are provided.notrue
run-gateRun MCP preflight gate when config and server are provided.nofalse
run-proxy-dry-runRun MCP proxy preflight in dry-run mode when config and server are provided.nofalse
run-attack-graphRun runtime attack graph when trace is provided.notrue
run-reportGenerate Markdown, HTML, and JSON Watchtower reports.notrue
run-attestationGenerate a tamper-evident evidence bundle from produced artifacts.notrue
namedescription
report-jsonWatchtower report JSON path.
sarifWatchtower SARIF path.
agent-bomAgentBOM JSON path.
evidence-bundleEvidence bundle JSON path.
proxy-auditMCP proxy audit JSON path.