OnionClawCAUTION
Provide AI agents with full Tor network access and dark web data through a zero-config OpenClaw skill or standalone tool.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://github.com/JacobJandon/OnionClaw/blob/main/LICENSE) [](https://github.com/JacobJandon/OnionClaw/actions/workflows/ci.yml) [](https://github.com/JacobJandon/OnionClaw)
by JacobJandon
OpenClaw skill + standalone tool — full Tor / dark web access for AI agents
OnionClaw gives AI agents full access to the Tor network and .onion hidden services. It runs as an OpenClaw skill (drop-in, zero config beyond a .env file) and also works standalone from any terminal.
Based on the SICRY engine — 18 dark web search engines, Robin OSINT pipeline, four LLM analysis modes.
# As an OpenClaw skill: cp -r OnionClaw ~/.openclaw/skills/onionclaw # → agent now has 7 dark web commands available in every session # Standalone: python3 check_tor.py # verify Tor python3 search.py --query "ransomware healthcare" python3 pipeline.py --query "acme.com data leak" --mode corporate
⚠️ The Rabbit Hole
Autonomous agents paired with the Tor network will be one of the most dangerous automation stacks on the internet within the next five years. OnionClaw is living proof that the rabbit hole goes deeper than most people think.
This tool is built for legitimate OSINT, threat intelligence, and security research. But the same primitives — anonymous routing, bulk scraping, AI-driven synthesis, zero-attribution browsing, automated identity rotation — are precisely what make this combination genuinely dangerous in the wrong hands.
This is not a warning tucked in fine print. It is the whole point of writing it down openly.
What the stack
1f0eaab2c8beOBSERVED · 2026-10-06Exposed tools (14)
13 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
sicry_analyze_nollm | read | return analyze_nollm(content, query=query) |
sicry_ask | read | return ask(content, query=query, mode=mode, custom_instructions=custom_instructions) |
sicry_check_engines | read | return check_search_engines(max_workers=max_workers, _cached=cached) |
sicry_check_tor | read | return check_tor() |
sicry_crawl | read | result = crawl(seed_url, max_depth=max_depth, max_pages=max_pages) |
sicry_crawl_export | read | return crawl_export(job_id) |
sicry_extract_keywords | read | return extract_keywords(text, top_n=top_n) |
sicry_renew_identity | read | return renew_identity() |
sicry_search | read | return search(query, max_results=max_results, mode=mode) |
sicry_to_csv | read | return to_csv(results) |
sicry_to_stix | read | return to_stix(results, query=query, report_text=report_text) |
sicry_watch_add | write | return { |
sicry_watch_check | read | return watch_check() |
sicry_watch_list | read | return watch_list() |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (9 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (10)
OLLAMA_BASE_URL=http://127.0.0.1:11434
LLAMACPP_BASE_URL=http://127.0.0.1:8080
OLLAMA_URL = os.getenv("OLLAMA_BASE_URL", "http://127.0.0.1:11434")LLAMACPP_URL = os.getenv("LLAMACPP_BASE_URL", "http://127.0.0.1:8080")Claw_Onion_1.9.zip
return hashlib.md5(normalised[:4096].encode(), usedforsecurity=False).hexdigest()
fp = hashlib.md5(combined.encode(), usedforsecurity=False).hexdigest()
fp = hashlib.md5(fp_source.encode(), usedforsecurity=False).hexdigest()
requests, beautifulsoup4, python-dotenv, stem
OnionClaw gives AI agents full access to the Tor network and .onion hidden services. It runs as an [OpenClaw](https://github.com/openclaw/openclaw) skill (drop-in, zero config beyond a `.env` file) an
Gates applied: no_behavioural_pass.
1f0eaab2c8befull audit observations/trust-audit/mcp-server/christinminor459__onionclaw-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 1f0eaab2c8be | CAUTION | B | 89 | first audit |
Questions
What is the OnionClaw MCP server?
Provide AI agents with full Tor network access and dark web data through a zero-config OpenClaw skill or standalone tool.
What tools does OnionClaw expose?
14 in total: 13 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is OnionClaw safe to connect to an agent?
With care. The audit graded it B (89/100) and found 10 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does OnionClaw need?
It reads ANTHROPIC_API_KEY, GEMINI_API_KEY, OPENAI_API_KEY and TOR_CONTROL_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (1f0eaab2c8be), read on 2026-10-06. The repository is watched and re-audited when it changes.