Atlas / MCP servers / christinminor459 / OnionClaw

OnionClawCAUTION

mcp/christinminor459/onionclaw-1

Provide AI agents with full Tor network access and dark web data through a zero-config OpenClaw skill or standalone tool.

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
14 13r · 1w · 0d
Transport
—
License
NOASSERTION
Stars
341
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://github.com/JacobJandon/OnionClaw/blob/main/LICENSE) [](https://github.com/JacobJandon/OnionClaw/actions/workflows/ci.yml) [](https://github.com/JacobJandon/OnionClaw)

by JacobJandon

OpenClaw skill + standalone tool — full Tor / dark web access for AI agents

OnionClaw gives AI agents full access to the Tor network and .onion hidden services. It runs as an OpenClaw skill (drop-in, zero config beyond a .env file) and also works standalone from any terminal.

Based on the SICRY engine — 18 dark web search engines, Robin OSINT pipeline, four LLM analysis modes.

# As an OpenClaw skill:
cp -r OnionClaw ~/.openclaw/skills/onionclaw
# → agent now has 7 dark web commands available in every session

# Standalone:
python3 check_tor.py        # verify Tor
python3 search.py --query "ransomware healthcare"
python3 pipeline.py --query "acme.com data leak" --mode corporate

⚠️ The Rabbit Hole

Autonomous agents paired with the Tor network will be one of the most dangerous automation stacks on the internet within the next five years. OnionClaw is living proof that the rabbit hole goes deeper than most people think.

This tool is built for legitimate OSINT, threat intelligence, and security research. But the same primitives — anonymous routing, bulk scraping, AI-driven synthesis, zero-attribution browsing, automated identity rotation — are precisely what make this combination genuinely dangerous in the wrong hands.

This is not a warning tucked in fine print. It is the whole point of writing it down openly.

What the stack

Read from source at commit 1f0eaab2c8beOBSERVED · 2026-10-06
02

Exposed tools (14)

13 read · 1 write · 0 destructive.

ToolRiskDescription
sicry_analyze_nollmreadreturn analyze_nollm(content, query=query)
sicry_askreadreturn ask(content, query=query, mode=mode, custom_instructions=custom_instructions)
sicry_check_enginesreadreturn check_search_engines(max_workers=max_workers, _cached=cached)
sicry_check_torreadreturn check_tor()
sicry_crawlreadresult = crawl(seed_url, max_depth=max_depth, max_pages=max_pages)
sicry_crawl_exportreadreturn crawl_export(job_id)
sicry_extract_keywordsreadreturn extract_keywords(text, top_n=top_n)
sicry_renew_identityreadreturn renew_identity()
sicry_searchreadreturn search(query, max_results=max_results, mode=mode)
sicry_to_csvreadreturn to_csv(results)
sicry_to_stixreadreturn to_stix(results, query=query, report_text=report_text)
sicry_watch_addwritereturn {
sicry_watch_checkreadreturn watch_check()
sicry_watch_listreadreturn watch_list()
03

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (9 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (10)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
.env.example:33
OLLAMA_BASE_URL=http://127.0.0.1:11434
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
.env.example:37
LLAMACPP_BASE_URL=http://127.0.0.1:8080
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
sicry.py:143
OLLAMA_URL         = os.getenv("OLLAMA_BASE_URL", "http://127.0.0.1:11434")
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
sicry.py:145
LLAMACPP_URL       = os.getenv("LLAMACPP_BASE_URL", "http://127.0.0.1:8080")
LOWInventory / provenance · inv.binary · CWE-1104
.github/ISSUE_TEMPLATE/Claw_Onion_1.9.zip
Claw_Onion_1.9.zip
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
sicry.py:888
return hashlib.md5(normalised[:4096].encode(), usedforsecurity=False).hexdigest()
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
sicry.py:912
fp = hashlib.md5(combined.encode(), usedforsecurity=False).hexdigest()
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
sicry.py:2299
fp = hashlib.md5(fp_source.encode(), usedforsecurity=False).hexdigest()
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
requests, beautifulsoup4, python-dotenv, stem
Why it matters. 4 requirement(s) not pinned with ==
Fix. pin exact versions
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
README.md:15
OnionClaw gives AI agents full access to the Tor network and .onion hidden services. It runs as an [OpenClaw](https://github.com/openclaw/openclaw) skill (drop-in, zero config beyond a `.env` file) an

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha 1f0eaab2c8befull audit observations/trust-audit/mcp-server/christinminor459__onionclaw-1.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-061f0eaab2c8beCAUTIONB89first audit
05

Questions

What is the OnionClaw MCP server?

Provide AI agents with full Tor network access and dark web data through a zero-config OpenClaw skill or standalone tool.

What tools does OnionClaw expose?

14 in total: 13 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is OnionClaw safe to connect to an agent?

With care. The audit graded it B (89/100) and found 10 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does OnionClaw need?

It reads ANTHROPIC_API_KEY, GEMINI_API_KEY, OPENAI_API_KEY and TOR_CONTROL_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (1f0eaab2c8be), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement