SocialClawBLOCK
Social media scheduling CLI and OpenClaw skill for AI agents posting to X, LinkedIn, Instagram, Facebook Pages, TikTok, Discord, Telegram, YouTube, Reddit, WordPress, and Pinterest.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
SocialClaw
Social media scheduling CLI and OpenClaw skill for AI agents posting to X, LinkedIn, Instagram, Facebook Pages, TikTok, Discord, Telegram, YouTube, Reddit, WordPress, and Pinterest.
Official Website: getsocialclaw.com · Dashboard · npm · Skill Bundle
[getsocialclaw.com](https://getsocialclaw.com) is the official SocialClaw website — the hosted dashboard, API, and account sign-up all live there.
This repo is the public home for:
- the
socialclawnpm CLI - the OpenClaw and ClawHub skill bundle
- the Claude Code plugin and
/socialclawcommand asset - public usage docs, provider notes, and schedule examples
Install
npm install -g socialclaw socialclaw login socialclaw accounts list --json
Install as an AI agent skill (Claude Code, Cursor, Cline, Codex, and more):
npx skills add ndesv21/socialclaw
What the CLI covers
- workspace API key login and hosted dashboard bootstrap
- browser OAuth connect plus manual Discord and Telegram connect
- hosted asset upload and deletion
- schedule validation, ca
4aeaa6095d24OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add socialclaw --env SOCIALCLAW_API_KEY=${SOCIALCLAW_API_KEY} -- npx -y [email protected]Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (3 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (8)
**Telegram** (`telegram`) — bot-based posting. Connected manually with a bot token and `chat_id` or `@channelusername`, not via OAuth. One optional image or video per post.
- open the API key section
- open the API key section
- open the API key section
- open the API key section
- open the API key section
**Telegram** (`telegram`) — bot-based posting. Connected manually with a bot token and `chat_id` or `@channelusername`, not via OAuth. One optional image or video per post.
Gates applied: critical_finding, no_behavioural_pass, undeclared_transfer.
4aeaa6095d24full audit observations/trust-audit/mcp-server/ndesv21__socialclaw.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 4aeaa6095d24 | BLOCK | D | 69 | first audit |
Questions
What is the SocialClaw MCP server?
Social media scheduling CLI and OpenClaw skill for AI agents posting to X, LinkedIn, Instagram, Facebook Pages, TikTok, Discord, Telegram, YouTube, Reddit, WordPress, and Pinterest.
Is SocialClaw safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does SocialClaw need?
It reads SC_API_KEY and SOCIALCLAW_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does SocialClaw run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as socialclaw at 0.1.22.
How current is this page?
The grade is for one exact copy of the source (4aeaa6095d24), read on 2026-10-07. The repository is watched and re-audited when it changes.