SwarmClawBLOCK
Open-source self-hosted AI agent runtime and multi-agent framework for autonomous agent swarms. Agent memory, MCP tools, schedules, delegation, and 23+ LLM providers (Claude, GPT, Gemini, OpenRouter, Ollama). A practical Claude Code and LangChain alternative.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://github.com/swarmclawai/swarmclaw/actions/workflows/ci.yml) [](https://github.com/swarmclawai/swarmclaw/releases) [](https://www.npmjs.com/package/@swarmclawai/swarmclaw)
The self-hosted AI agent runtime and multi-agent framework for autonomous agents. Open-source agent swarms with durable agent memory, MCP tools, skills, delegation, schedules, and 23+ LLM providers — a practical Claude Code and LangChain alternative.
SwarmClaw is an open-source, self-hosted AI agent runtime and multi-agent framework. Run autonomous AI agents, agent swarms, and orchestrators with heartbeats, schedules, delegation, agent memory, runtime skills, and reviewed conversation-to-skill learning — across OpenClaw gateways, Claude, GPT, Gemini, OpenRouter, Ollama, and 23+ other providers. Use it as your AI agent dashboard, agent orchestration platform, and home base for self-hosted multi-agent AI workflows.
GitHub: https://github.com/swarmclawai/swarmclaw Docs: https://swarmclaw.ai/docs Website: https://swarmclaw.ai Discord: https://discord.gg/sbEavS8cPV Extension tutorial: https://swarmclaw.ai/docs/extension-tutorial
Screenshots
957c9e3d8e01OBSERVED · 2026-09-28Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add swarmclaw --env ACCESS_KEY=${ACCESS_KEY} --env COPILOT_GITHUB_TOKEN=${COPILOT_GITHUB_TOKEN} --env CREDENTIAL_SECRET=${CREDENTIAL_SECRET} --env ELEVENLABS_API_KEY=${ELEVENLABS_API_KEY} -- npx -y @swarmclawai/[email protected]{
"mcpServers": {
"swarmclaw": {
"command": "npx",
"args": [
"-y",
"@swarmclawai/[email protected]"
],
"env": {
"ACCESS_KEY": "${ACCESS_KEY}",
"COPILOT_GITHUB_TOKEN": "${COPILOT_GITHUB_TOKEN}",
"CREDENTIAL_SECRET": "${CREDENTIAL_SECRET}",
"ELEVENLABS_API_KEY": "${ELEVENLABS_API_KEY}"
}
}
}
}Exposed tools (190)
157 read · 31 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
Alpha | read | Test agent |
Analyst | read | |
Anthropic | read | Claude models — strong for coding, analysis, and long-form reasoning. |
Assistant | read | |
Atlas | read | A helpful GPT-powered assistant. |
Backlog | read | Separate workspace |
Beta | read | Second test agent |
Bolt | read | A low-latency assistant powered by Groq. |
Builder | read | Implements ideas, ships changes, and drives technical execution. |
Claude | read | A helpful Claude-powered assistant. |
CodeBot | read | |
Coordinator | read | |
Data-Driven | read | Always backs claims with numbers. |
DeepInfra | read | Fast serverless inference for popular open-source models. |
DeepSeek | read | High-value reasoning and coding models from DeepSeek. |
Default | read | Default workspace |
Design | read | Handles design critique and UI polish |
Editor | read | Improves structure, tone, and quality before publishing. |
Gardener | read | Nurtures ideas and lets them grow. |
Gemini | read | A helpful Gemini-powered assistant. |
Grok | read | A helpful assistant powered by xAI Grok. |
Groq | read | Very fast inference with open and reasoning model options. |
Hal | read | |
Hal2k | read | Heartbeat hygiene test |
Hermes | read | A runtime-backed assistant powered by Hermes Agent. |
Local | read | A local assistant running through Ollama. |
Maker | read | Executes focused work items assigned by the user or other agents. |
Mistral | read | A helpful assistant powered by Mistral. |
Molly | read | |
Mosaic | read | A helpful assistant powered by Together AI. |
Nebius | read | Wide catalog of 60+ open-source models via Nebius Token Factory. |
Ollama | write | Run local open-source models or connect to Ollama Cloud. |
OpenAI | read | Great default for most users. Fast, reliable GPT models. |
OpenClaw | write | Deploy or connect official-only local and remote OpenClaw gateways, then map starter agents across your swarm by role, tag, or use case. |
OpenRouter | read | One API key for a broad multi-provider model catalog through an OpenAI-compatible API. |
Operator | read | Coordinates tasks, delegates work, and keeps the workspace moving. |
Ops | read | Handles deploys and infrastructure |
Probe | read | Heartbeat probe |
Prototyper | read | Builds first, specs later. |
Requesty | read | One API key for a broad multi-provider model catalog through an OpenAI-compatible gateway, with caching, failover, and cost controls. |
Researcher | read | Collects facts, compares options, and produces structured findings. |
Reviewer | read | Reviews plans and outputs for bugs, regressions, and quality gaps. |
Rex | read | A helpful agent |
Room | read | |
Router | read | A helpful assistant powered through OpenRouter. |
Sidekick | read | A versatile assistant for everyday work, planning, and follow-through. |
Spark | read | A helpful assistant powered by Fireworks AI. |
SwarmClaw | read | AI agent orchestration |
Swarmy | read | Helpful coding agent |
Test | read | |
TokenMix | read | One OpenAI-compatible API relay for Claude, OpenAI, Gemini, DeepSeek, Qwen, and other hosted models. |
Triager | read | Triages inbound messages into urgent, reply-needed, and informational buckets. |
Worker | read | |
Writer | read | |
a | read | Tool A |
a2a | read | A2A Protocol gateway |
activity | read | Query activity feed events |
agents | read | Manage agents |
approvals | read | List and resolve human-loop approvals |
artifacts | read | Resolve evidence artifacts for runs, missions, and tasks |
auth | read | Access key auth helpers |
autonomy | read | Inspect supervisor incidents and reflection output |
b | read | Tool B |
browser | read | Control a persistent browser profile. Supports low-level actions plus higher-level workflows like read_page, extract_links, extract_form_fields, extract_table, fill_form, submit_form, scroll_until, download_file, complete_web_task, profile, and reset_profile. |
c | read | Tool C |
chatroom-policy | read | Configure chatroom delegation refusal policies |
chatrooms | read | Manage multi-agent chatrooms |
chats | read | Manage agent chats and runtime controls |
claude-skills | read | Read local Claude skills directory metadata |
clawhub | write | Browse and install ClawHub skills |
config-versions | read | Inspect and restore configuration version history |
connector_message_tool | write | Send and manage outbound messages across chat platforms. |
connectors | read | Manage chat connectors |
context_status | read | Check token usage and context window limits. |
context_summarize | read | Compact conversation history to free up space. |
cost-attribution | read | Aggregate LLM cost by billing-code tags |
credentials | read | Manage encrypted provider credentials |
custom_media_sender | write | Send rendered media somewhere special. |
cwd_check | read | |
daemon | read | Control background daemon |
delegate | read | Delegate to a specialized backend (Claude, Codex, OpenCode, Gemini, Copilot, Droid, Cursor, Qwen) for code tasks: writing files, refactoring, debugging, code generation, and multi-file edits. Supports background jobs with action=status|list|wait|cancel. |
delegation-jobs | read | Delegation job status |
deploy-repair-workflow | write | Repair deploy regressions in a stable order. |
deploy-triage | write | Triage deploy issues in a fixed order. |
deploy-verification | write | Verify deploy blockers, config, and smoke checks. |
deploy-workflow-learned | write | Agent-scoped deploy workflow. |
dirs | read | Directory listing and native picker |
dispatch-helper.md | read | Dispatch through manage_skills status. |
documents | read | Manage documents |
echo | read | |
edit_file | write | Surgically replace a specific string within a file. |
email | write | Send an email or check email configuration status. For sending: provide to, subject, and body. Optionally include html for rich formatting. |
eval | write | Run agent evaluation scenarios |
execute | write | Execute a bash script. Supports curl, jq, awk, sed, grep, and 70+ Unix commands. |
extension_creator_tool | destructive | Create, read, edit, delete, or get the spec for writing new SwarmClaw extensions. Always call get_spec first to learn the correct format. |
extensions | read | Manage extensions and marketplace |
external-agents | read | Manage external agent runtimes |
files | read | Serve and manage local files |
gateways | read | Manage named OpenClaw gateway profiles |
generate_image | read | Generate an image from a text prompt. The image is saved and a download link is returned. Use descriptive, detailed prompts for best results. |
generic-notes | read | Store notes. |
github | read | GitHub operations |
github-sync | write | Stored GitHub flow. |
github-sync.md | write | Sync GitHub issues into tasks. |
goals | read | Manage goal hierarchy |
google-workspace-helper | read | Automate Google Workspace docs and sheets. |
google_workspace | write | Run a Google Workspace CLI ( |
greet | read | Greets |
healthz | read | Public liveness probe |
incident-triage | write | Triage incidents in a stable order. |
ip | read | Get local IP/port metadata |
knowledge | read | Manage knowledge base entries |
learned-skills | read | Inspect agent-scoped learned skills |
logs | destructive | Read or clear app logs |
mailbox | read | Work with email inboxes. Actions: status, list_messages, list_threads, search_messages, read_message, download_attachment, reply, wait_for_email. |
manage_capabilities | read | Discover available built-in tools or external extensions, search marketplaces, or request access to a direct tool or extension id with action= |
manage_platform | read | Unified fallback tool for managing SwarmClaw resources when a more specific |
manage_protocols | read | Structured orchestration workflows. Actions: list_templates, create_run (title, participantAgentIds, templateId or steps), run_status (runId), list_runs, run_action (runId, runAction: start|pause|resume|cancel), create_template (name, description, tags), run_events (runId). |
mcp-registry | read | Browse the public SwarmDock MCP Registry |
mcp-servers | read | Manage MCP server configurations |
meeting-notes | read | Capture meeting notes and follow-ups. |
memories | read | Alias of memory command group |
memory | read | Manage memory entries |
memory-images | read | Fetch stored memory image assets |
memory_get | read | Read a specific memory entry by id or key after search, keeping context focused. |
memory_search | read | Search durable long-term memory for prior work, decisions, dates, people, preferences, or todos from earlier conversations. Prefer this before broader history tools. |
memory_tool | write | Advanced long-term memory system. Store and update canonical durable facts across conversations; store/update will merge matching memories and retire superseded variants. Search defaults to durable memories unless sources explicitly include archive or working. |
memory_update | write | Update or correct an existing durable memory when new information supersedes the old value. |
missions | read | Manage autonomous missions |
monitor_tool | write | Create durable waits that resume the agent when conditions trigger. Actions: create_watch, wait_until, wait_for_http, wait_for_file, wait_for_task, wait_for_webhook, wait_for_page_change, list_watches, get_watch, cancel_watch. For sys_info/ping/log tailing, use shell instead. |
my_custom_tool | read | Does something useful |
notifications | read | Manage in-app notifications |
openclaw | read | OpenClaw discovery, gateway control, and runtime APIs |
openclaw_browser | read | Control a browser through the OpenClaw CLI. |
openclaw_nodes | read | Interact with connected OpenClaw nodes/devices. |
openclaw_workspace | read | Versioning tools for the OpenClaw workspace. |
operations | read | Operator triage and readiness summaries |
other-agent-skill | read | Should not leak. |
perf | read | Inspect or control runtime perf tracing |
pin_context | read | Pin a fact, failed approach, blocker, or discovery to working memory so it survives context compaction and flows to subagents. |
ping | read | |
platform | read | Consolidated platform tool. Use dotted action names: |
portability | write | Export and import agent configurations |
preview-server | read | Manage preview dev servers |
projects | read | Manage projects |
prompt-helper.md | read | Guidance-only workflow. |
protocols | read | Manage Structured Session runs and templates |
providers | read | Manage providers and model overrides |
read_file | read | Reads a file |
replicate | write | Run AI models on Replicate. Actions: run (create and wait for prediction), get (check prediction status), cancel (stop a prediction), get_model (model details), search (find models), status (check config). |
request_tool_access | read | Ask the user for access to an extension I don\ |
runs | write | Session run queue/history |
schedule_wake | write | Schedule a wake event (reminder) for yourself in this chatroom. |
schedules | read | Manage schedules |
search | read | Global search across app resources |
secrets | read | Manage reusable encrypted secrets |
send_file | write | Send a file to the user in chat. Use the returned /api/uploads/... links exactly as provided. |
sessions_tool | read | Manage sessions and check identity. Actions: identity (whoami), list, history, spawn, update. |
settings | write | Read/update app settings |
setup | read | Setup and provider validation helpers |
share | read | Public share links for missions, skills, and sessions |
shell | write | Execute commands and manage processes. Use for git, curl, long-lived servers, and other host CLI tools. |
skill-suggestions | read | Review conversation-derived skill drafts |
skills | read | Manage reusable skills |
souls | read | Browse and manage soul library templates |
spawn_subagent | read | Delegate tasks to other agents. |
swarmdock | read | SwarmDock marketplace |
swarmfeed | read | SwarmFeed social network |
system-status | read | Lightweight system health summary |
t | read | d |
tasks | read | Manage task board items |
test-hub-skill | read | A ClawHub test skill. |
tool1 | read | My cool tool |
tts | read | Text-to-speech endpoint |
upload | write | Upload raw file/blob |
uploads | read | Manage uploaded artifacts |
usage | read | Usage and cost summary |
version | write | Version and update checks |
wallets | read | Manage agent wallets |
web | read | Unified web access tool. Actions: search (web search), fetch/extract (read URL content), crawl (bounded same-origin crawl), api (raw HTTP request with method/headers/body). |
web_crawl | write | Crawl a small set of pages starting from one URL. Same-origin by default, bounded by maxPages and maxDepth. |
web_extract | read | Extract readable content from a URL with title and source URL included. |
web_fetch | read | Read a specific URL and return readable page text. |
web_search | read | Search the web and return ranked results with URLs and snippets. |
webhooks | write | Manage and trigger webhooks |
whatsapp-voice-fallback | read | Use a fallback voice synthesis path for WhatsApp delivery. |
whatsapp-voice-fallback-v2 | read | Revised fallback. |
workflow-states | read | Manage customizable task workflow states |
workspace-helper | read | Automate workspace docs. |
workspaces | read | Manage logical workspaces (multi-workspace scaffolding) |
Trust audit
BLOCKgrade D · trust 66/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | FAIL |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (10 observation(s))
- Network
- declared (17 observation(s))
- Shell
- declared (5 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (25)
skill-save-payload.ts
placeholder="~/.ssh/id_ed25519"
'**/.ssh/id_*', '**/.env', '**/.env.local', '**/.gnupg/**',
: { rejectUnauthorized: false, checkServerIdentity: () => undefined }const tlsSocket = tls.connect({ socket, host: cfg.host, rejectUnauthorized: false }, () => {socket = tls.connect({ ...connectOpts, rejectUnauthorized: false }, () => {{ code: 'credential_theft', re: /\b(?:api key|token|password|secret|credential)s?\b[\s\S]{0,40}\b(?:send|share|reveal|print|dump|exfiltrat)/i, note: 'asks for secrets or credentials' },const DEV_URL_DEFAULT = 'http://127.0.0.1:3456'
const url = `http://127.0.0.1:${port}`const baseUrl = `http://127.0.0.1:${port}`if curl -sS --max-time 1 "http://127.0.0.1:${CHROME_CDP_PORT}/json/version" >/dev/null; then'🐶', '🐱', '🐭', '🐹', '🐰', '🦊', '🐻', '🐼', '🐻❄️', '🐨',
'❤️🔥', '❤️🩹', '❣️', '💕', '💞', '💓', '💗', '💖', '💘', '💝',
'🚩', '🎌', '🏴', '🏳️', '🏳️🌈', '🏳️⚧️', '🏴☠️', '🇺🇸', '🇬🇧', '🇯🇵',
extension_creator_tool, logs
.eslint-baseline.json
skill-save-payload.test.ts
const hash = crypto.createHash('sha1')outputHashes.add(crypto.createHash('sha1').update(output.slice(0, 500)).digest('hex').slice(0, 12))const signature = crypto.createHash('sha1')const textHash = crypto.createHash('sha1').update(text).digest('hex').slice(0, 16)return createHash('sha1').update(input).digest('hex').slice(0, 8)const repoRoot = path.resolve(path.dirname(new URL(import.meta.url).pathname), '../../../..')
const repoRoot = path.resolve(path.dirname(new URL(import.meta.url).pathname), '../../../../..')
'../../../lib/server/__fixtures__/fake-mcp-stdio-server.mjs',
Gates applied: no_behavioural_pass.
957c9e3d8e01full audit observations/trust-audit/mcp-server/swarmclawai__swarmclaw.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-28 | 957c9e3d8e01 | BLOCK | D | 66 | first audit |
Questions
What is the SwarmClaw MCP server?
Open-source self-hosted AI agent runtime and multi-agent framework for autonomous agent swarms. Agent memory, MCP tools, schedules, delegation, and 23+ LLM providers (Claude, GPT, Gemini, OpenRouter, Ollama). A practical Claude Code and LangChain alternative.
What tools does SwarmClaw expose?
190 in total: 157 read-only, 31 that write, and 2 that can delete or overwrite (extension_creator_tool, logs). Every one is listed on this page with its risk.
Is SwarmClaw safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (66/100) and found 6 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does SwarmClaw need?
It reads ACCESS_KEY, COPILOT_GITHUB_TOKEN, CREDENTIAL_SECRET, ELEVENLABS_API_KEY, EXA_API_KEY, FACTORY_API_KEY, GEMINI_API_KEY, GH_TOKEN, GITHUB_PERSONAL_ACCESS_TOKEN, GITHUB_TOKEN, GOOGLE_API_KEY and OLLAMA_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does SwarmClaw run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @swarmclawai/swarmclaw at 1.9.40.
How current is this page?
The grade is for one exact copy of the source (957c9e3d8e01), read on 2026-09-28. The repository is watched and re-audited when it changes.