ClawQL (danielsmithdevelopment/ClawQL) is an MCP server listed on the M8ven Trust Index. M8ven has not graded it: there is no public source to read and no endpoint we can reach, so there is nothing for us to inspect. No publisher has claimed this listing.

C
Emerging
74/100
2 months ago

ClawQL

An MCP server for API discovery and execution with a token-efficient search -> execute workflow over OpenAPI, Google Discovery, and optional native GraphQL and gRPC sources.

Emerging. No concerning findings. Grades remain capped until the project builds reputation through adoption. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

Code Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

danielsmithdevelopment

Source: Glama

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 16 credentials: BENCHMARK_JIRA_ISSUE_KEY, CLAWQL_BEARER_TOKEN, CLAWQL_DASHBOARD_SYNC_TOKEN, CLAWQL_DASHBOARD_VAULT_TOKEN, CLAWQL_FETCH_PAPERLESS_K8S_TOKEN, CLAWQL_MCP_JWT_HS256_SECRET, CLAWQL_ONYX_API_TOKEN, CLAWQL_PAPERLESS_API_TOKEN, CLAWQL_STIRLING_API_KEY, GITHUB_TOKEN, GITHUB_USE_GH_TOKEN, ONYX_API_TOKEN, PAPERLESS_API_TOKEN, STIRLING_API_KEY, VAULT_TOKEN, WORKFLOW_JIRA_PROJECT_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies1 medium1 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

mediumturbo@2.5.4GHSA-hcf7-66rw-9f5r

Trubo: Login callback CSRF/session fixation

lowturbo@2.5.4GHSA-3qcw-2rhx-2726

Turbo: Unexpected local code execution during Yarn Berry detection

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configBENCHMARK_CLOUDFLARE_ZONE_ID
configBENCHMARK_GOOGLE_PARENT
🔐 secretBENCHMARK_JIRA_ISSUE_KEY
configBENCHMARK_LIVE
configCLAWQL_API_BASE_URL
configCLAWQL_AUDIT_MAX_ENTRIES
🔐 secretCLAWQL_BEARER_TOKEN
configCLAWQL_BRIDGE_DIRECT_SHIM
configCLAWQL_BRIDGE_PANGUARD_COMMAND
configCLAWQL_BRIDGE_SHIM_PATH
configCLAWQL_BRIDGE_STREAMABLE_HTTP_JSON_RESPONSE
configCLAWQL_BRIDGE_UPSTREAM_HOST
configCLAWQL_BRIDGE_UPSTREAM_MCP_PATH
configCLAWQL_BRIDGE_UPSTREAM_PORT
configCLAWQL_BRIDGE_UPSTREAM_URL
configCLAWQL_BUNDLED_OFFLINE
configCLAWQL_CUCKOO_METRICS
configCLAWQL_DASHBOARD_ALLOW_K8S_SYNC
configCLAWQL_DASHBOARD_E2E
configCLAWQL_DASHBOARD_E2E_DEPLOYMENT
configCLAWQL_DASHBOARD_E2E_NAMESPACE
configCLAWQL_DASHBOARD_E2E_SECRET_NAME
configCLAWQL_DASHBOARD_K8S_DEPLOYMENT
configCLAWQL_DASHBOARD_K8S_NAMESPACE
configCLAWQL_DASHBOARD_K8S_SECRET_NAME
configCLAWQL_DASHBOARD_OPENCLAW_CHAT_URL
🔐 secretCLAWQL_DASHBOARD_SYNC_TOKEN
configCLAWQL_DASHBOARD_VAULT_ADDR
configCLAWQL_DASHBOARD_VAULT_MOUNT
configCLAWQL_DASHBOARD_VAULT_NAMESPACE
configCLAWQL_DASHBOARD_VAULT_PATH
configCLAWQL_DASHBOARD_VAULT_POD
🔐 secretCLAWQL_DASHBOARD_VAULT_TOKEN
configCLAWQL_ENABLE_DOCUMENTS
configCLAWQL_FETCH_K8S_NAMESPACE
configCLAWQL_FETCH_PAPERLESS_K8S_PORT
configCLAWQL_FETCH_PAPERLESS_K8S_SERVICE
🔐 secretCLAWQL_FETCH_PAPERLESS_K8S_TOKEN
configCLAWQL_FETCH_PROVIDER_SPECS_LOCALHOST_DEFAULTS
configCLAWQL_FETCH_PROVIDER_SPECS_SKIP_SELF_HOSTED
configCLAWQL_FETCH_STIRLING_K8S_FALLBACK
configCLAWQL_FETCH_STIRLING_K8S_PORT
configCLAWQL_FETCH_STIRLING_K8S_SECRET_NAME
configCLAWQL_FETCH_STIRLING_K8S_SERVICE
configCLAWQL_GOOGLE_TOP50_SPECS
configCLAWQL_HTTP_HEADERS
configCLAWQL_MCP_GRPC_ADDR
configCLAWQL_MCP_HTTP_URL
configCLAWQL_MCP_JWT_ATR_CLAIM
configCLAWQL_MCP_JWT_AUDIENCE
configCLAWQL_MCP_JWT_ENABLED
🔐 secretCLAWQL_MCP_JWT_HS256_SECRET
configCLAWQL_MCP_JWT_ISSUER
configCLAWQL_MCP_JWT_JWKS_URL
configCLAWQL_MCP_JWT_PUBLIC_KEY_PEM_PATH
configCLAWQL_MCP_TRANSPORT
configCLAWQL_MCP_URL
🔐 secretCLAWQL_ONYX_API_TOKEN
configCLAWQL_OPENCLAW_AGENT_ID
configCLAWQL_OPENCLAW_BIN
configCLAWQL_OPENCLAW_BOOTSTRAP_TOOLS_ONLY
configCLAWQL_PANGUARD_PROXY_DEBUG
configCLAWQL_PANGUARD_PROXY_PLUGIN
🔐 secretCLAWQL_PAPERLESS_API_TOKEN
configCLAWQL_PREGENERATE_ONLY
configCLAWQL_PROVIDERall-providers npx clawql-mcp
🔐 secretCLAWQL_STIRLING_API_KEY
configCLAWQL_TARGET_NAMESPACE
configENABLE_GRPC
configENABLE_GRPC_REFLECTION
configGH_OWNER
configGH_REPO
configGITHUB_COMMIT_LIMIT
configGITHUB_OWNER
configGITHUB_REPO
🔐 secretGITHUB_TOKEN
🔐 secretGITHUB_USE_GH_TOKEN
configGOTENBERG_OPENAPI_PIN_URL
configGRPC_BIND
configGRPC_HOST
configGRPC_MAX_MESSAGE_LENGTH
configGRPC_PORT
configGRPC_TLS_CA_PATH
configGRPC_TLS_CERT_PATH
configGRPC_TLS_KEY_PATH
configGRPC_TLS_REQUIRE_CLIENT_CERT
configJIRA_SITE
configKUBE_CONTEXT
configLH_MIN_A11Y
configLH_MIN_BP
configLH_MIN_PERF
configLH_MIN_SEO
configMCP_HOST
configMCP_PATH
configMCP_PORT
configMCP_PROTOCOL_VERSION
configN8N_BASE_URL
🔐 secretONYX_API_TOKEN
configOPENCLAW_AGENT_ID
configOPENCLAW_AGENT_TIMEOUT_SEC
configOPENCLAW_BIN
configOPENCLAW_CHAT_BRIDGE_PORT
🔐 secretPAPERLESS_API_TOKEN
configREPO_DESCRIPTION
configRESUME_PDF
🔐 secretSTIRLING_API_KEY
configSTIRLING_OPENAPI_PATHS
configVAULT_ADDR
configVAULT_BIN
🔐 secretVAULT_TOKEN
configWORKFLOW_CREATE_JIRA_ISSUE
configWORKFLOW_JIRA_ASSIGNEE_ACCOUNT_ID
configWORKFLOW_JIRA_ASSIGNEE_DISPLAY_NAME
configWORKFLOW_JIRA_ISSUE_TYPE_NAME
configWORKFLOW_JIRA_LABELS
🔐 secretWORKFLOW_JIRA_PROJECT_KEY
configWORKFLOW_MCP_EXECUTE
configWORKFLOW_MCP_EXECUTE_EACH_QUERY
configWORKFLOW_MCP_HEALTH_QUIET
configWORKFLOW_MCP_HEALTH_WAIT_SEC
configWORKFLOW_MCP_SEARCH_LIMIT
configWORKFLOW_MCP_SEARCH_LIMIT_QUICK
configWORKFLOW_PREVIEW_JIRA_REQUEST
Deployment configuration, supplied by whoever hosts the server. Users are not asked for these.
deployNEXT_PUBLIC_CLAWQL_DASHBOARD_K8S_DEPLOYMENT
deployNEXT_PUBLIC_CLAWQL_DASHBOARD_K8S_NAMESPACE
deployNEXT_PUBLIC_CLAWQL_DASHBOARD_K8S_SECRET_NAME
deployPORT
// quality suggestions

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

4/4 tools missing one or more hints — echo (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); hello (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); e2e_bridge_ping (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +1 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Tool inputs are validated

Only 1/4 tool handlers declare input schemas (25%)

Declare an inputSchema with zod/joi/yup on every tool definition.

Tool handlers catch errors

Only 0/4 tool handlers wrap calls in try/catch (0%)

Wrap each tool handler body in try/catch and return a structured error response.

Tool test coverage

2/4 tools referenced in tests (50%)

Write tests that reference each tool by name so every tool has at least one test.

Shell command execution

4 child_process calls — runs shell commands

Prefer library functions over shell-outs. If you must shell out, ensure all inputs are properly escaped.

Dependency freshness

2/26 production deps stale: swagger2openapi@2022-06-27 (4y), node-fetch@2023-11-30 (2.5y)

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 6 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/danielsmithdevelopment-clawql-2iu97z)](https://m8ven.ai/mcp/danielsmithdevelopment-clawql-2iu97z)
Shows your grade and updates automatically. Prefer no grade? Append ?variant=verified to the badge URL.
commit: 3273e4664a04f7681904abba7f5c4500b6552d8b
code hash: 2f3032e7a45ec13ee7a4acbcf306d4ffe7446b6e4bd820ab1704f404eab0e002
verified: 6/12/2026, 10:31:31 AM
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client