Atlas / MCP servers / freema / OpenClaw

OpenClawCAUTION

mcp/freema/openclaw

🦞 MCP server for OpenClaw - secure bridge between Claude.ai and your self-hosted OpenClaw assistant with OAuth2 authentication

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
7 5r · 2w · 0d
Transport
sse · stdio · streamable-http
License
MIT
Stars
185
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/openclaw-mcp) [](https://github.com/freema/openclaw-mcp/actions/workflows/ci.yml) [](https://opensource.org/licenses/MIT) [](https://github.com/freema/openclaw-mcp/pkgs/container/openclaw-mcp) [](https://openclaw-mcp.cloud)

🦞 Model Context Protocol (MCP) server for OpenClaw AI assistant integration.

Demo

Why I Built This

Hey! I created this MCP server because I didn't want to rely solely on messaging channels to communicate with OpenClaw. What really excites me is the ability to connect OpenClaw to the Claude web UI. Essentially, my chat can delegate tasks to my Claw bot, which then handles everything else — like spinning up Claude Code to fix issues for me.

Think of it as an AI assistant orchestrating another AI assistant. Pretty cool, right?

Quick Start

Docker (Recommended)

Pre-built images are published to GitHub Container Registry on every release.

docker pull ghcr.io/freema/openclaw-mcp:latest

Create a docker-compose.yml:

services:
mcp-bridge:
image: ghcr.io/freema/openclaw-mcp:latest
container_name: openclaw-mcp
restart: unless-stopped
ports:
- "3000:3000"
environment:
- OPENCLAW_URL=http://host.docker.internal
Read from source at commit f425c6c037acOBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add openclaw-mcp --env OPENCLAW_GATEWAY_TOKEN=${OPENCLAW_GATEWAY_TOKEN} --env OPENCLAW_GATEWAY_TOKEN=${OPENCLAW_GATEWAY_TOKEN} -- npx -y [email protected]
claude-code (oci)
claude mcp add openclaw-mcp:1.5.0 --env OPENCLAW_GATEWAY_TOKEN=${OPENCLAW_GATEWAY_TOKEN} --env OPENCLAW_GATEWAY_TOKEN=${OPENCLAW_GATEWAY_TOKEN} -- docker run -i --rm ghcr.io/freema/openclaw-mcp:1.5.0:None
03

Exposed tools (7)

5 read · 2 write · 0 destructive.

ToolRiskDescription
openclaw_chatwriteSend a message to OpenClaw and get a response
openclaw_chat_asyncwriteSend a message to OpenClaw asynchronously. Returns a task_id immediately that can be polled for results. Use this for potentially long-running conversations.
openclaw_instancesreadList all configured OpenClaw instances. Shows instance names, URLs, and which is the default. Use instance names in other tools to target a specific OpenClaw gateway.
openclaw_statusreadGet OpenClaw gateway status and health information
openclaw_task_cancelreadCancel a pending task. Only works for tasks that haven
openclaw_task_listreadList all tasks. Optionally filter by status, session, or instance.
openclaw_task_statusreadCheck the status of an async task. Returns status, and result if completed.
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (3 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (14)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
.env.example:11
OPENCLAW_URL=http://127.0.0.1:18789
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
Taskfile.yml:98
OPENCLAW_URL: http://127.0.0.1:18789
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
src/config/constants.ts:11
'PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSIxMjgiIGhlaWdodD0iMTI4IiB2aWV3Qm94PSIwIDAgMTI4IDEyOCIgZmlsbD0ibm9uZSI+PGRlZnM+PGxpbmVhckdyYWRpZW50IGlkPSJiZyIgeDE9IjAlIiB5MT0iMCUiIHgyPSI
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/__tests__/auth/oauth.test.ts:2
import { OpenClawAuthProvider, OpenClawClientsStore } from '../../auth/provider.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/__tests__/mcp/tasks/manager.test.ts:2
import { taskManager } from '../../../mcp/tasks/manager.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/__tests__/mcp/tools/tasks.test.ts:12
import { InstanceRegistry } from '../../../openclaw/registry.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/__tests__/mcp/tools/tasks.test.ts:13
import { taskManager } from '../../../mcp/tasks/manager.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/__tests__/mcp/tools/tasks.test.ts:19
} from '../../../mcp/tools/tasks.js';
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:97
"OPENCLAW_URL": "http://127.0.0.1:18789",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/configuration.md:11
| `OPENCLAW_URL`           | OpenClaw gateway URL                    | `http://127.0.0.1:18789` |
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/configuration.md:198
Matching is exact (scheme, host, path). A common mistake is registering `https://claude.ai/oauth/callback`, which does **not** match and makes Claude.ai fail with `Unregistered redirect_uri`. If you a
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, yargs, @types/node, @types/yargs, @typescript-eslint/eslint-plugin, @typescript-eslint/parser, eslint, eslint-config-prettier
Why it matters. 14 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
SECURITY.md:11
| Unauthorized access | High | OAuth2 authentication, API keys |
Why it matters. asks the agent to read credentials
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
docs/openclaw-zh-quickstart.md:24
curl -fsSL https://openclaw.ai/install.sh | bash

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha f425c6c037acfull audit observations/trust-audit/mcp-server/freema__openclaw.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-06f425c6c037acCAUTIONB89first audit
06

Questions

What is the OpenClaw MCP server?

🦞 MCP server for OpenClaw - secure bridge between Claude.ai and your self-hosted OpenClaw assistant with OAuth2 authentication

What tools does OpenClaw expose?

7 in total: 5 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is OpenClaw safe to connect to an agent?

With care. The audit graded it B (89/100) and found 14 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does OpenClaw need?

It reads AUTH_ENABLED, MCP_CLIENT_SECRET, OAUTH_ENABLED and OPENCLAW_GATEWAY_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does OpenClaw run?

It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as openclaw-mcp at 1.7.0.

How current is this page?

The grade is for one exact copy of the source (f425c6c037ac), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement