Atlas / MCP servers / jacobjandon / OnionClaw

OnionClawCAUTION

mcp/jacobjandon/onionclaw

OnionClawTM — OpenClaw skill for full Tor dark web access: search .onion sites, fetch hidden services, rotate identity, run OSINT pipeline, craw.

Verdict
CAUTION
Grade
B
Trust score
88 /100
Exposed tools
14 13r · 1w · 0d
Transport
—
License
NOASSERTION
Stars
68
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://github.com/JacobJandon/OnionClaw/blob/main/LICENSE) [](https://github.com/JacobJandon/OnionClaw/actions/workflows/ci.yml) [](https://github.com/JacobJandon/OnionClaw)

by JacobJandon

OpenClaw skill + standalone tool — full Tor / dark web access for AI agents

OnionClaw gives AI agents full access to the Tor network and .onion hidden services. It runs as an OpenClaw skill (drop-in, zero config beyond a .env file) and also works standalone from any terminal.

Based on the SICRY engine — 18 dark web search engines, Robin OSINT pipeline, four LLM analysis modes.

# As an OpenClaw skill:
cp -r OnionClaw ~/.openclaw/skills/onionclaw
# → agent now has 7 dark web commands available in every session

# Standalone:
python3 check_tor.py        # verify Tor
python3 search.py --query "ransomware healthcare"
python3 pipeline.py --query "acme.com data leak" --mode corporate

⚠️ The Rabbit Hole

Autonomous agents paired with the Tor network will be one of the most dangerous automation stacks on the internet within the next five years. OnionClaw is living proof that the rabbit hole goes deeper than most people think.

This tool is built for legitimate OSINT, threat intelligence, and security research. But the same primitives — anonymous routing, bulk scraping, AI-driven synthesis, zero-attribution browsing, automated identity rotation — are precisely what make this combination genuinely dangerous in the wrong hands.

This is not a warning tucked in fine print. It is the whole point of writing it down openly.

W

Read from source at commit 4baa99d3da34OBSERVED · 2026-10-07
02

Exposed tools (14)

13 read · 1 write · 0 destructive.

ToolRiskDescription
sicry_analyze_nollmreadreturn analyze_nollm(content, query=query)
sicry_askreadreturn ask(content, query=query, mode=mode, custom_instructions=custom_instructions)
sicry_check_enginesreadreturn check_search_engines(max_workers=max_workers, _cached=cached)
sicry_check_torreadreturn check_tor()
sicry_crawlreadresult = crawl(seed_url, max_depth=max_depth, max_pages=max_pages)
sicry_crawl_exportreadreturn crawl_export(job_id)
sicry_extract_keywordsreadreturn extract_keywords(text, top_n=top_n)
sicry_renew_identityreadreturn renew_identity()
sicry_searchreadreturn search(query, max_results=max_results, mode=mode)
sicry_to_csvreadreturn to_csv(results)
sicry_to_stixreadreturn to_stix(results, query=query, report_text=report_text)
sicry_watch_addwritereturn {
sicry_watch_checkreadreturn watch_check()
sicry_watch_listreadreturn watch_list()
03

Trust audit

CAUTIONgrade B · trust 88/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (9 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (9)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
.env.example:33
OLLAMA_BASE_URL=http://127.0.0.1:11434
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
.env.example:37
LLAMACPP_BASE_URL=http://127.0.0.1:8080
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
sicry.py:143
OLLAMA_URL         = os.getenv("OLLAMA_BASE_URL", "http://127.0.0.1:11434")
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
sicry.py:145
LLAMACPP_URL       = os.getenv("LLAMACPP_BASE_URL", "http://127.0.0.1:8080")
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
sicry.py:912
return hashlib.md5(normalised[:4096].encode(), usedforsecurity=False).hexdigest()
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
sicry.py:936
fp = hashlib.md5(combined.encode(), usedforsecurity=False).hexdigest()
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
sicry.py:2433
fp = hashlib.md5(fp_source.encode(), usedforsecurity=False).hexdigest()
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
requests, beautifulsoup4, python-dotenv, stem
Why it matters. 4 requirement(s) not pinned with ==
Fix. pin exact versions
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
README.md:15
OnionClaw gives AI agents full access to the Tor network and .onion hidden services. It runs as an [OpenClaw](https://github.com/openclaw/openclaw) skill (drop-in, zero config beyond a `.env` file) an

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 4baa99d3da34full audit observations/trust-audit/mcp-server/jacobjandon__onionclaw.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-074baa99d3da34CAUTIONB88first audit
05

Questions

What is the OnionClaw MCP server?

OnionClawTM — OpenClaw skill for full Tor dark web access: search .onion sites, fetch hidden services, rotate identity, run OSINT pipeline, craw.

What tools does OnionClaw expose?

14 in total: 13 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is OnionClaw safe to connect to an agent?

With care. The audit graded it B (88/100) and found 9 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does OnionClaw need?

It reads ANTHROPIC_API_KEY, GEMINI_API_KEY, MISTRAL_API_KEY, OPENAI_API_KEY, OPENROUTER_API_KEY, PERPLEXITY_API_KEY, REPLICATE_API_KEY, TOGETHER_API_KEY and TOR_CONTROL_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (4baa99d3da34), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement