CodexClaw (MackDing/CodexClaw) is an MCP server listed on the M8ven Trust Index. M8ven has not graded it yet. No publisher has claimed this listing.
Telegram bot for Claude Code and Codex CLI with MCP routing, multi-agent orchestration, cron jobs, and access controls.
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
MackDing
Source: github_topic
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
simple-git is vulnerable to Remote Code Execution
undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives
undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse
undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent
undici WebSocket client vulnerable to denial of service via fragment count bypass
ALLOWED_USER_IDSWhitelist-only access () is mandatoryCODEX_ARGSCODEX_BACKENDOn =sdk, Telegram streams structured Codex SDK events and persists thread IDs per projectCODEX_COMMANDCodex not producing output: verify CODEX_BACKEND, , and CODEX_WORKDIRCODEX_SDK_ADDITIONAL_DIRECTORIESCODEX_SDK_APPROVAL_POLICYCODEX_SDK_CONFIGCODEX_SDK_NETWORK_ACCESS_ENABLEDCODEX_SDK_REASONING_EFFORTCODEX_SDK_SANDBOX_MODEIf is unset, the bot now defaults SDK threads to Full Access: danger-full-access with approvalPolicy=never. Set it explicitly to workspace-write or read-only only if you want a more restricted mode.CODEX_SDK_SKIP_GIT_REPO_CHECKCODEX_SDK_WEB_SEARCH_MODECODEX_WORKDIRKeep scoped to a safe workspace rootCRON_DAILY_SUMMARYDaily summary schedule: (default 0 9 )CRON_TIMEZONEE2E_TEST_COMMANDGITHUB_DEFAULT_BRANCHGITHUB_DEFAULT_WORKDIRGITHUB_TOKENGitHub API failures: verify scope (repo) and account permissionsMCP_SERVERSPROACTIVE_USER_IDSTarget users:SHELL_ALLOWED_COMMANDSSHELL_DANGEROUS_COMMANDSIf you allow write commands, mark high-risk prefixes in and require /sh --confirm ...SHELL_ENABLEDSHELL_MAX_OUTPUT_CHARSSHELL_READ_ONLYKeep =true unless you have a strong reason to allow write commandsSHELL_TIMEOUT_MSSTATE_FILERuntime state is persisted to , so /mcp enabledisable, /skill onoff, /language, /verbose, and per-project Codex conversation slots survive bot restartsSTREAM_BUFFER_CHARSSTREAM_THROTTLE_MSThrottle: controlled by (default 1200)TELEGRAM_API_BASETelegram API blocked: set TELEGRAM_PROXY_URL (HTTP proxy like http://127.0.0.1:7890) or run a local Bot API server and setTELEGRAM_PROXY_URLTelegram API blocked: set (HTTP proxy like http://127.0.0.1:7890) or run a local Bot API server and set TELEGRAM_API_BASEWORKSPACE_ROOT/repo - list switchable git projects underProduction dependencies are patched
0 critical, 5 high severity in production deps — simple-git@3.33.0 (high), undici@7.24.5 (high)
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
Dependency freshness
1/12 production deps stale: lodash.throttle@2022-06-19 (4.2y)
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/mackding/codexclaw)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check