# cs_dbg_watch

Manage a persistent set of C# watch expressions and evaluate them in the current stopped frame. Pass add/remove/clear to mutate the set (all optional), then every current watch is re-evaluated and returned. Call with no mutation args to just re-read the watches after a step/continue. Expressions are evaluated in DAP watch context (intended to be side-effect-free), so this is not gated; the results are only meaningful while the program is stopped at a breakpoint.

Agent View of the PolicyLayer registry record for `cs_dbg_watch`. HTML page: https://policylayer.com/tools/breakpoint-mcp/cs-dbg-watch

## Facts

- Tool: `cs_dbg_watch`
- Server: Breakpoint (`breakpoint-mcp`) — https://policylayer.com/tools/breakpoint-mcp.md
- Install: `npx -y breakpoint-mcp`
- Homepage: https://www.npmjs.com/package/breakpoint-mcp
- Risk category: Read (Low risk)
- Registry record: grade F, identity unverified
- Server rate-limited: no
- Parameters: 4
- Recommended policy verdict: Allowed

## Parameters

| Parameter | Type | Required | Description |
| --- | --- | --- | --- |
| `add` | array | no | Expressions to add to the watch set |
| `clear` | boolean | no | Clear all watches before applying add (default false) |
| `remove` | array | no | Expressions to remove from the watch set |
| `frame_id` | integer | no | Frame id from cs_dbg_stack_trace; omit for the top frame |

Parameters from the server's own tool schema.

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "cs_dbg_watch",
    "arguments": {}
  }
}
```

## Why cs_dbg_watch is rated Low

Although the tool has mutation operations (`add`/`remove`/`clear`), these mutate only the local watch expression set, not the debugged program's state. The core function is evaluation/inspection of variables at a breakpoint, which is a read operation. The explicit note that expressions are 'intended to be side-effect-free' in DAP watch context confirms this is fundamentally a debugging inspection tool.

From the tool's own definition: "Tool description states it 'Manage a persistent set of C# watch expressions and evaluate them in the current stopped frame' and 'Expressions are evaluated in DAP `watch` context (intended to be side-effect-free)'."

Risk signals: Bulk/mass operation — affects multiple targets

## Use case

AI agents call cs_dbg_watch to retrieve information from Breakpoint without modifying anything. It is typically the context-gathering step in research, monitoring, and reporting workflows, before the agent takes action elsewhere.

## Recommended policy (PolicyLayer)

Verdict: **Allowed**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches Breakpoint:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "cs_dbg_watch": {}
  }
}
```

## Other tools on Breakpoint (273)

- `anim_delete` — Destructive — https://policylayer.com/tools/breakpoint-mcp/anim-delete.md
- `anim_remove_key` — Destructive — https://policylayer.com/tools/breakpoint-mcp/anim-remove-key.md
- `filesystem_move` — Destructive — https://policylayer.com/tools/breakpoint-mcp/filesystem-move.md
- `gd_rename` — Destructive — https://policylayer.com/tools/breakpoint-mcp/gd-rename.md
- `inputmap_erase_action` — Destructive — https://policylayer.com/tools/breakpoint-mcp/inputmap-erase-action.md
- `mp_wire_rpc` — Destructive — https://policylayer.com/tools/breakpoint-mcp/mp-wire-rpc.md
- `node_delete` — Destructive — https://policylayer.com/tools/breakpoint-mcp/node-delete.md
- `project_remove_autoload` — Destructive — https://policylayer.com/tools/breakpoint-mcp/project-remove-autoload.md
- `resource_save` — Destructive — https://policylayer.com/tools/breakpoint-mcp/resource-save.md
- `resource_set_import_settings` — Destructive — https://policylayer.com/tools/breakpoint-mcp/resource-set-import-settings.md
- `runtime_node_remove` — Destructive — https://policylayer.com/tools/breakpoint-mcp/runtime-node-remove.md
- `runtime_peer_stop` — Destructive — https://policylayer.com/tools/breakpoint-mcp/runtime-peer-stop.md
- `scene_close` — Destructive — https://policylayer.com/tools/breakpoint-mcp/scene-close.md
- `scene_reload` — Destructive — https://policylayer.com/tools/breakpoint-mcp/scene-reload.md
- `shader_set_code` — Destructive — https://policylayer.com/tools/breakpoint-mcp/shader-set-code.md
- `tilemap_clear` — Destructive — https://policylayer.com/tools/breakpoint-mcp/tilemap-clear.md
- `vcs_restore` — Destructive — https://policylayer.com/tools/breakpoint-mcp/vcs-restore.md
- `vcs_stash` — Destructive — https://policylayer.com/tools/breakpoint-mcp/vcs-stash.md
- `cs_dbg_attach` — Execute — https://policylayer.com/tools/breakpoint-mcp/cs-dbg-attach.md
- `cs_dbg_continue` — Execute — https://policylayer.com/tools/breakpoint-mcp/cs-dbg-continue.md
- `cs_dbg_launch` — Execute — https://policylayer.com/tools/breakpoint-mcp/cs-dbg-launch.md
- `cs_dbg_restart` — Execute — https://policylayer.com/tools/breakpoint-mcp/cs-dbg-restart.md
- `cs_dbg_set_breakpoints` — Execute — https://policylayer.com/tools/breakpoint-mcp/cs-dbg-set-breakpoints.md
- `cs_dbg_set_exception_breakpoints` — Execute — https://policylayer.com/tools/breakpoint-mcp/cs-dbg-set-exception-breakpoints.md
- `cs_dbg_set_variable` — Execute — https://policylayer.com/tools/breakpoint-mcp/cs-dbg-set-variable.md
- `cs_dbg_step` — Execute — https://policylayer.com/tools/breakpoint-mcp/cs-dbg-step.md
- `dbg_attach` — Execute — https://policylayer.com/tools/breakpoint-mcp/dbg-attach.md
- `dbg_continue` — Execute — https://policylayer.com/tools/breakpoint-mcp/dbg-continue.md
- `dbg_data_breakpoints` — Execute — https://policylayer.com/tools/breakpoint-mcp/dbg-data-breakpoints.md
- `dbg_goto` — Execute — https://policylayer.com/tools/breakpoint-mcp/dbg-goto.md
- …and 243 more: https://policylayer.com/tools/breakpoint-mcp.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=breakpoint-mcp · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/breakpoint-mcp
