# MCPWatch

What this client asked https://www.pathwren.workers.dev for, from that host's own request log.
Window: 2026-09-01 03:49:49Z to 2026-09-03 03:53:31Z UTC. Generated 2026-09-03.

## User-agent strings, exactly as they arrived

- `MCPWatch/0.1.0 (+mcpwatch@iyre.com) longitudinal MCP security research` — 38 request(s), 1 address(es), 2026-09-01 03:49:49Z to 2026-09-03 03:53:31Z

- Requests: 38
- Distinct addresses (salted hashes, never published): 1
- Distinct paths: 6
- Visits (30-minute gap rule): 3
- Status codes: 200×31, 202×7
- Accept headers: application/json, text/event-stream
- Our classifier called it: agent×38 (ours, from the user-agent)

## What it asked for, in order

1. `/c/mcp-registry-official/mcp/doctor` — 2026-09-01 03:49:49Z — 200
2. `/c/mcp-registry-official/mcp` — 2026-09-01 03:49:49Z — 200
3. `/c/mcp-registry-official/mcp/triage` — 2026-09-01 03:49:49Z — 200
4. `/c/mcp-registry-official/mcp/netcheck` — 2026-09-02 03:48:13Z — 200
5. `/c/mcp-registry-official/mcp/robots` — 2026-09-02 03:48:14Z — 200
6. `/c/mcp-registry-official/mcp/lint` — 2026-09-03 03:53:03Z — 200

## What it asked for that did not exist

Nothing.

## Verification

Not observed. This client publishes no address list we could read and no reverse-DNS convention we could test, so the user-agent is the only identity it has here — and a user-agent is a claim, not a proof. Anyone can send this string.

## What it publishes about you

Not observed. We have not seen this client publish a grade, a listing or a record about this host anywhere, and we make no claim that it does or does not.

## Documentation it names

mailto:mcpwatch@iyre.com

JSON: https://www.pathwren.workers.dev/bot/mcpwatch.json · all clients: https://www.pathwren.workers.dev/data/observed-clients.json
