AgentClaw (Negai-ai/AgentClaw) is an MCP server listed on the M8ven Trust Index. It scores 74 out of 100, grade C. It declares 48 tools. No publisher has claimed this listing.

C
Emerging
74/100

AgentClaw

AgentClaw turns one-sentence ideas into reusable Claw capabilities. Build less boilerplate with declarative workflows, computer browser code file control, MCP, Skills, memory, knowledge bases, tracing, scheduling, and API/MCP publishing.

Emerging. No concerning findings. Grades remain capped until the project builds reputation through adoption. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

Code Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

Negai-ai

Source: github_code

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 10 credentials: WECOM_SECRET, MCP_TOKEN, ADMIN_TOKEN, WORKFLOW_API_KEY, PG_PASSWORD, REDIS_PASSWORD, MINIO_ACCESS_KEY, MINIO_SECRET_KEY, MILVUS_TOKEN, FALLBACK_API_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configVITE_API_PORT
configWECOM_BOT_ID
configWECOM_SCENE
🔐 secretWECOM_SECRET
configWECOM_WS_URL
configAGENTCLAW_PROJECT_DIR
configEXPORT_MCP_TOOLS
configAGENTCLAW_LOG_FILE
configLOG_FILE
configAGENTCLAW_DATA_DIR
configAGENTCLAW_DASHBOARD_MODE
configADMIN_DASHBOARD_PORT
configHOST
configAGENTCLAW_ALLOW_QUERY_TOKENS
configREBUILD_DASHBOARD
configPIP_INDEX_URL
configCONDA_DEFAULT_ENV
configDOWNLOAD_BASE_URL
configSEARXNG_BASE_URL
configAGENTCLAW_ALLOW_GLOBAL_RELAY_CONFIG
configAGENTCLAW_INTERNAL_URL
configAGENTCLAW_URL
configCOMSPEC
configSUDO_COMMAND_TIMEOUT
configCDP_PORT
configBROWSER_HEADLESS
configAGENTCLAW_MCP_TOOL_TIMEOUT
configDOWNLOAD_MAX_FILE_SIZE_BYTES
configDOWNLOAD_MAX_FILE_SIZE_MB
configDOWNLOAD_MAX_TTL_SECONDS
configAGENTCLAW_FILE_LOCK_TIMEOUT
configAGENTCLAW_FILE_LOCK_TTL
🔐 secretMCP_TOKEN
configPYTHONPATH
configAgentClaw_SERVER_BASE_URL
🔐 secretADMIN_TOKEN
🔐 secretWORKFLOW_API_KEY
configPG_PORT
configREDIS_PORT
configADMINER_PORT
configMINIO_API_PORT
configMINIO_CONSOLE_PORT
configMILVUS_PORT
configMILVUS_HTTP_PORT
configPG_HOST
configPG_USER
🔐 secretPG_PASSWORD
configPG_DATABASE
configPG_POOL_MIN_SIZE
configPG_POOL_MAX_SIZE
configREDIS_HOST
🔐 secretREDIS_PASSWORD
configREDIS_POOL_MAX_CONNECTIONS
configWORKFLOW_TIMEOUT
configWORKFLOW_RECURSION_LIMIT
configMAX_TOOL_ROUNDS
configMAX_CONTEXT_MESSAGES
configTOOL_RESULT_MAX_LENGTH
configMAX_MESSAGE_LENGTH
configUPLOAD_DIR
configFILE_STORAGE_DIR
configMAX_UPLOAD_SIZE_MB
configMINIO_ENDPOINT
🔐 secretMINIO_ACCESS_KEY
🔐 secretMINIO_SECRET_KEY
configMINIO_BUCKET
configMINIO_SECURE
configKNOWLEDGEBASE_ENABLED
configKNOWLEDGEBASE_STORAGE_DIR
configKNOWLEDGEBASE_PARSER_CACHE_DIR
configKNOWLEDGEBASE_BACKEND
configKNOWLEDGEBASE_RETRIEVAL_MODE
configKNOWLEDGEBASE_PREFER_BUILTIN_HYBRID
configKNOWLEDGEBASE_DENSE_CANDIDATE_MULTIPLIER
configKNOWLEDGEBASE_KEYWORD_CANDIDATE_MULTIPLIER
configKNOWLEDGEBASE_RERANK_CANDIDATE_MULTIPLIER
configMILVUS_URI
🔐 secretMILVUS_TOKEN
configMILVUS_COLLECTION_PREFIX
configMILVUS_METRIC_TYPE
configMILVUS_INDEX_TYPE
configKNOWLEDGEBASE_DEFAULT_TOP_K
configKNOWLEDGEBASE_CHUNK_SIZE
configKNOWLEDGEBASE_CHUNK_OVERLAP
configDEFAULT_KNOWLEDGEBASE_ID
configKNOWLEDGEBASE_DEFAULT_EMBEDDING_MODEL
configKNOWLEDGEBASE_DEFAULT_RERANK_MODEL
configKNOWLEDGEBASE_DEFAULT_LLM_MODEL
configSCHEDULER_ENABLED
configSCHEDULER_TIMEZONE
configSCHEDULER_MAX_WORKERS
configSCHEDULER_COALESCE
configSCHEDULER_MAX_INSTANCES
configKUBERNETES_SERVICE_HOST
configAGENTCLAW_CONTENT_SECURITY_POLICY
configAGENTCLAW_MCP_CONNECT_TIMEOUT
configLOG_CONSOLE_LEVEL
configAGENTCLAW_LLM_FAILURE_DUMP_DIR
🔐 secretFALLBACK_API_KEY
configFALLBACK_BASE_URL
configFALLBACK_MODEL_NAME
configAGENTCLAW_PUBLIC_TOOL_POLICY
configDISPLAY
configWAYLAND_DISPLAY
configSKILL_ATTESTATION_MAX_SESSIONS
configSKILL_ATTESTATION_TTL_SECONDS
configPROMPT_RELOAD_INTERVAL
configREDIS_DB
Deployment configuration, supplied by whoever hosts the server. Users are not asked for these.
deployPORT
// quality suggestions

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

48/48 tools missing one or more hints — search_code (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); syntax_check (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); read_code (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +45 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Tool test coverage

Only 14/48 tools referenced in tests (29%)

Write tests that reference each tool by name so every tool has at least one test.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 3 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/negai-ai/agentclaw)](https://m8ven.ai/mcp/negai-ai/agentclaw)
Shows your grade and updates automatically. Prefer no grade? Append ?variant=verified to the badge URL.
commit: 034efd10375f5f7ca7f59e9ee50c1e398ed894e7
code hash: acb5523fdb0b17f5e5bccbd36fde1eb8d7bc8412f8315db9e0f37fbfa2d58b75
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client