48
/ 100
1 month ago
github_topic

CodexClaw

Telegram bot for Claude Code and Codex CLI with MCP routing, multi-agent orchestration, cron jobs, and access controls.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Known vulnerabilities in dependencies: 1 critical, 5 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
⚠️
Tests do not pass
Either the test suite is broken or the code regressed. Either way the published behaviour can’t be verified by the publisher’s own tests.
🔐
You'll be asked for 2 credentials: BOT_TOKEN, GITHUB_TOKEN
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies1 critical5 high

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

criticalsimple-git@3.28.0GHSA-r275-fr43-pm7q

simple-git has blockUnsafeOperationsPlugin bypass via case-insensitive protocol.allow config key enables RCE

high@modelcontextprotocol/sdk@1.13.2GHSA-345p-7cg4-v4c7

@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse

high@modelcontextprotocol/sdk@1.13.2GHSA-8r9q-7v3j-jr4g

Anthropic's MCP TypeScript SDK has a ReDoS vulnerability

high@modelcontextprotocol/sdk@1.13.2GHSA-w48q-cv73-mx4w

Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default

highsimple-git@3.28.0GHSA-hffm-xvc3-vprc

simple-git is vulnerable to Remote Code Execution

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configALLOWED_USER_IDS123456789,987654321
🔐 secretBOT_TOKEN123456789:telegram-token
configCODEX_ARGS
configCODEX_BACKENDOn =sdk, Telegram streams structured Codex SDK events and persists thread IDs per project
configCODEX_COMMANDCodex not producing output: verify CODEX_BACKEND, , and CODEX_WORKDIR
configCODEX_SDK_ADDITIONAL_DIRECTORIES["/abs/path/extra-worktree"]
configCODEX_SDK_APPROVAL_POLICY
configCODEX_SDK_CONFIG
configCODEX_SDK_NETWORK_ACCESS_ENABLED
configCODEX_SDK_REASONING_EFFORT
configCODEX_SDK_SANDBOX_MODEdanger-full-access
configCODEX_SDK_SKIP_GIT_REPO_CHECK
configCODEX_SDK_WEB_SEARCH_MODE
configCODEX_WORKDIRKeep scoped to a safe workspace root
configCRON_DAILY_SUMMARYDaily summary schedule: (default 0 9 )
configCRON_TIMEZONEAsia/Shanghai
configE2E_TEST_COMMANDnpx playwright test --reporter=line
configGITHUB_DEFAULT_BRANCH
configGITHUB_DEFAULT_WORKDIR
🔐 secretGITHUB_TOKENGitHub API failures: verify scope (repo) and account permissions
configMCP_SERVERS
configPROACTIVE_USER_IDSTarget users:
configREASONING_RENDER_MODEquote block (if =quote)
configSHELL_ALLOWED_COMMANDS["pwd","ls","git status","git diff --stat","npm test","npm run check"]
configSHELL_DANGEROUS_COMMANDS["git add","git commit","git push","rm","mv","cp","npm publish"]
configSHELL_ENABLED
configSHELL_MAX_OUTPUT_CHARS
configSHELL_READ_ONLYKeep =true unless you have a strong reason to allow write commands
configSHELL_TIMEOUT_MS
configSTATE_FILE.codex-telegram-claws-state.json
configSTREAM_BUFFER_CHARS
configSTREAM_THROTTLE_MSThrottle: controlled by (default 1200)
configTELEGRAM_API_BASETelegram API blocked: set TELEGRAM_PROXY_URL (HTTP proxy like http://127.0.0.1:7890) or run a local Bot API server and set
configTELEGRAM_EXPECTED_USERNAME(optional)
configTELEGRAM_PROXY_URLTelegram API blocked: set (HTTP proxy like http://127.0.0.1:7890) or run a local Bot API server and set TELEGRAM_API_BASE
configTELEGRAM_SMOKE_CHAT_ID(optional)
configWORKSPACE_ROOT/repo - list switchable git projects under
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 4 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/mackding-codexclaw-sqcydb)](https://m8ven.ai/mcp/mackding-codexclaw-sqcydb)
commit: 263be7c8281e90bf6604a65a4f327f385df60279
code hash: 4480cad4d89b8218dc31e7a236f94507b19f8e12c82e10f5c362eb001b4aef95
verified: 6/15/2026, 1:15:41 PM
view raw JSON →