An AI agent that claws through your network
Warning. Serious findings were identified. Review the full report before connecting. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
automateyournetwork
Source: github_code
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
BGP_LISTEN_PORTHUD_PORTNETCLAW_LOCAL_ASNETCLAW_ROUTER_IDNETCLAW_SESSION_BUDGET_USDRAG_DATA_DIRRAG_MAX_DOC_MBANALYSIS_QUERY_TIMEOUTANALYSIS_MAX_RESULT_ROWSANTA_USERNAMEANTA_PASSWORDANTA_ENABLE_PASSWORDANTA_VERIFY_TLSANTA_TIMEOUTCATALYST_CENTER_HOSTCATALYST_CENTER_USERNAMECATALYST_CENTER_PASSWORDCATALYST_CENTER_VERIFY_SSLMULTIVENDOR_WRITE_ENABLEDBGP_DAEMON_APIITSM_ENABLEDITSM_LAB_MODEOLLAMA_BASE_URLOLLAMA_TIMEOUTPCAP_UPLOAD_DIRNETCLAW_BGP_PEERSNETCLAW_OSPF_AREASNETCLAW_GRE_TUNNELSNETCLAW_LAB_MODETTS_OUTPUT_DIRTTS_DEFAULT_VOICETWILIO_ACCOUNT_SIDTWILIO_API_KEY_SIDTWILIO_API_SECRETTWILIO_PHONE_NUMBERTWILIO_WEBHOOK_URLTWITTER_REPLIES_ENABLEDANTHROPIC_API_KEYTWITTER_MENTION_POLL_INTERVALTWITTER_OAUTH2_ACCESS_TOKENTWITTER_OAUTH2_TOKENTWITTER_OAUTH2_REFRESH_TOKENTWITTER_CLIENT_IDTWITTER_CLIENT_SECRETTWITTER_API_KEYTWITTER_API_SECRETTWITTER_ACCESS_TOKENTWITTER_ACCESS_SECRETTWITTER_HEARTBEAT_ENABLEDTWITTER_HEARTBEAT_INTERVALAUVIK_USERNAMEAUVIK_API_KEYAUVIK_VERIFY_SSLAUVIK_TIMEOUTAUVIK_RATE_LIMITAUVIK_MAX_PAGESAUVIK_BASE_URLBATFISH_HOSTBATFISH_PORTBATFISH_NETWORKEVE_URLEVE_USEREVE_CONSOLE_HOSTEVE_SESSION_TTLEVE_VERIFY_SSLGNMI_MAX_SUBSCRIPTIONSGNS3_URLGNS3_USERGNS3_PASSWORDGNS3_VERIFY_SSLGNS3_TOKEN_TTLHALO_BASE_URLHALO_TENANTHALO_CLIENT_IDHALO_CLIENT_SECRETHALO_SCOPEHALO_AUTH_URLHALO_VERIFY_SSLHALO_TIMEOUTHALO_PAGE_SIZEHALO_MAX_PAGESHALO_RATE_LIMITIPFIX_PORTIPFIX_BIND_ADDRESSIPFIX_RETENTION_HOURSIPFIX_RATE_LIMITIPFIX_DEDUP_WINDOWMEMORY_DATA_DIRSNMPTRAP_PORTSNMPTRAP_BIND_ADDRESSSNMPTRAP_RETENTION_HOURSSNMPTRAP_RATE_LIMITSNMPTRAP_DEDUP_WINDOWSYSLOG_PORTSYSLOG_BIND_ADDRESSSYSLOG_RETENTION_HOURSSYSLOG_RATE_LIMITSYSLOG_DEDUP_WINDOWMCP_CALL_TIMEOUTEVE_LAB_ROOTEVE_RUNTIME_ROOTMULTIVENDOR_TIMEOUT_SMULTIVENDOR_LAB_GROUPSSERVICENOW_INSTANCE_URLSERVICENOW_USERNAMESERVICENOW_PASSWORDMULTIVENDOR_MAX_WORKERSTWILIO_AUTH_TOKENTWILIO_WEBHOOK_PORTOPENCLAW_GATEWAY_URLOPENCLAW_GATEWAY_TOKENCML_URLCML_USERNAMECML_PASSWORDGNS3_USERNAMEPAGERDUTY_API_KEYVOICE_MAX_CALL_MINUTESVOICE_WARN_MINUTESZABBIX_TOKENZABBIX_USERZABBIX_PASSWORDZABBIX_MCP_TRANSPORTAUTH_TYPEZABBIX_URLZABBIX_MCP_HOSTZABBIX_MCP_PORTZABBIX_MCP_STATELESS_HTTPMIST_MCP_URLMIST_API_TOKENMIST_API_HOSTMIST_ORG_IDAPI_KEYUE5_MCP_URLANALYSIS_MAX_FILE_BYTESANALYSIS_MAX_ROWSANALYSIS_EXTRA_ROOTSBGP_INTEL_AUDIT_LOGBGP_INTEL_MAX_RPSDOCUMENT_AUDIT_LOGDOCUMENT_OUTPUT_DIREVE_PASSWORDEVE_HTML5EVE_CACHE_TTLEVE_CACHE_MAX_ENTRIESEVE_MAX_PAGE_SIZEEVE_CONSOLE_USEREVE_CONSOLE_PASSWORDFORTINET_AUDIT_LOGGNMI_TARGETSGNMI_TLS_CA_CERTGNMI_TLS_CAGNMI_TLS_CLIENT_CERTGNMI_TLS_CERTGNMI_TLS_CLIENT_KEYGNMI_TLS_KEYGNMI_TLS_SKIP_VERIFYGNMI_DEFAULT_PORTGNMI_MAX_RESPONSE_SIZEVAULT_ADDRGOLDEN_CONFIG_POLL_INTERVALGOLDEN_CONFIG_JOB_TIMEOUTNAUTOBOT_URLNAUTOBOT_TOKENNAUTOBOT_VERIFY_SSLNAUTOBOT_TIMEOUTNSM_TIMEOUTOLLAMA_MODEL_FALLBACKBGP_API_PORTNETCLAW_MESH_OPENN2N_EDGE_WS_PING_INTERVALN2N_EDGE_WS_PING_TIMEOUTNETCLAW_MESH_ENDPOINTNETCLAW_LOCAL_IPV6NETCLAW_DRY_RUNN2N_ENABLEDN2N_DISPLAY_NAMEN2N_INVENTORY_REFRESH_SN2N_ROLEN2N_RISK_NAMEN2N_RISK_DESCRIPTIONN2N_ENABLED_STACKSN2N_BORDER_ENDPOINTN2N_MEMBER_IDN2N_IN2N_PORTN2N_ENROLLMENT_TOKENN2N_EDGE_WS_PORTN2N_CLAW_DOMAINN2N_CERT_RENEW_CHECK_STool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
454/454 tools missing one or more hints — analysis_status (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); analysis_datasets (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); analysis_query (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +451 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Destructive tools are labelled
2 tools perform destructive updates without destructiveHint — pdf_fill_form deletes at line 204 (dest.unlink(missing_ok=True)); batfish_upload_snapshot deletes at line 308 (shutil.rmtree(snap_dir, ignore_errors=True))
Add destructiveHint:true to any tool whose handler calls .delete(), .upsert(), .update(), unlink, rm, DELETE, DROP, REPLACE INTO, or any operation that overwrites existing data.
Descriptions match behaviour
2 tools describe read intent but their handlers mutate — pcap_summary (line 82: capinfos = subprocess.run(); gre_tunnel_status (line 349: result = subprocess.run()
Rename the tool, rewrite the description, or move the side-effect into a separate clearly-named tool.
Tool test coverage
134/454 tools referenced in tests (30%)
Write tests that reference each tool by name so every tool has at least one test.
Shell command execution
1 child_process/subprocess call in production code — runs shell commands (ui/netclaw-visual/server.js:1882)
Prefer library functions over shell-outs. If you must shell out, ensure all inputs are properly escaped.
Secrets stay with their owner
6 secret/sensitive values flow into network calls (CATALYST_CENTER_PASSWORD → dynamic, SERVICENOW_PASSWORD → dynamic) (14 other flows matched canonical API hosts)
Audit where credentials are sent. A NOTION_TOKEN should only reach api.notion.com — never a third-party host.
Secrets not logged
11 secret values sent to console.log
Redact or omit secret values from log output.
Tool description accuracy
pcap_summary: description implies read-only but handler writes/deletes/executes; gre_tunnel_status: description implies read-only but handler writes/deletes/executes
Update tool descriptions to accurately reflect all capabilities — especially write, delete, or execute operations.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/automateyournetwork-netclaw-1qfb6g)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check