Atlas / MCP servers / swarmclawai / SwarmClaw

SwarmClawBLOCK

mcp/swarmclawai/swarmclaw

Open-source self-hosted AI agent runtime and multi-agent framework for autonomous agent swarms. Agent memory, MCP tools, schedules, delegation, and 23+ LLM providers (Claude, GPT, Gemini, OpenRouter, Ollama). A practical Claude Code and LangChain alternative.

Verdict
BLOCK
Grade
D
Trust score
66 /100
Exposed tools
190 157r · 31w · 2d
Transport
stdio · streamable-http
License
MIT
Stars
685
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://github.com/swarmclawai/swarmclaw/actions/workflows/ci.yml) [](https://github.com/swarmclawai/swarmclaw/releases) [](https://www.npmjs.com/package/@swarmclawai/swarmclaw)

The self-hosted AI agent runtime and multi-agent framework for autonomous agents. Open-source agent swarms with durable agent memory, MCP tools, skills, delegation, schedules, and 23+ LLM providers — a practical Claude Code and LangChain alternative.

SwarmClaw is an open-source, self-hosted AI agent runtime and multi-agent framework. Run autonomous AI agents, agent swarms, and orchestrators with heartbeats, schedules, delegation, agent memory, runtime skills, and reviewed conversation-to-skill learning — across OpenClaw gateways, Claude, GPT, Gemini, OpenRouter, Ollama, and 23+ other providers. Use it as your AI agent dashboard, agent orchestration platform, and home base for self-hosted multi-agent AI workflows.

GitHub: https://github.com/swarmclawai/swarmclaw Docs: https://swarmclaw.ai/docs Website: https://swarmclaw.ai Discord: https://discord.gg/sbEavS8cPV Extension tutorial: https://swarmclaw.ai/docs/extension-tutorial

Screenshots

Read from source at commit 957c9e3d8e01OBSERVED · 2026-09-28
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add swarmclaw --env ACCESS_KEY=${ACCESS_KEY} --env COPILOT_GITHUB_TOKEN=${COPILOT_GITHUB_TOKEN} --env CREDENTIAL_SECRET=${CREDENTIAL_SECRET} --env ELEVENLABS_API_KEY=${ELEVENLABS_API_KEY} -- npx -y @swarmclawai/[email protected]
claude-desktop
{
  "mcpServers": {
    "swarmclaw": {
      "command": "npx",
      "args": [
        "-y",
        "@swarmclawai/[email protected]"
      ],
      "env": {
        "ACCESS_KEY": "${ACCESS_KEY}",
        "COPILOT_GITHUB_TOKEN": "${COPILOT_GITHUB_TOKEN}",
        "CREDENTIAL_SECRET": "${CREDENTIAL_SECRET}",
        "ELEVENLABS_API_KEY": "${ELEVENLABS_API_KEY}"
      }
    }
  }
}
03

Exposed tools (190)

157 read · 31 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
AlphareadTest agent
Analystread
AnthropicreadClaude models — strong for coding, analysis, and long-form reasoning.
Assistantread
AtlasreadA helpful GPT-powered assistant.
BacklogreadSeparate workspace
BetareadSecond test agent
BoltreadA low-latency assistant powered by Groq.
BuilderreadImplements ideas, ships changes, and drives technical execution.
ClaudereadA helpful Claude-powered assistant.
CodeBotread
Coordinatorread
Data-DrivenreadAlways backs claims with numbers.
DeepInfrareadFast serverless inference for popular open-source models.
DeepSeekreadHigh-value reasoning and coding models from DeepSeek.
DefaultreadDefault workspace
DesignreadHandles design critique and UI polish
EditorreadImproves structure, tone, and quality before publishing.
GardenerreadNurtures ideas and lets them grow.
GeminireadA helpful Gemini-powered assistant.
GrokreadA helpful assistant powered by xAI Grok.
GroqreadVery fast inference with open and reasoning model options.
Halread
Hal2kreadHeartbeat hygiene test
HermesreadA runtime-backed assistant powered by Hermes Agent.
LocalreadA local assistant running through Ollama.
MakerreadExecutes focused work items assigned by the user or other agents.
MistralreadA helpful assistant powered by Mistral.
Mollyread
MosaicreadA helpful assistant powered by Together AI.
NebiusreadWide catalog of 60+ open-source models via Nebius Token Factory.
OllamawriteRun local open-source models or connect to Ollama Cloud.
OpenAIreadGreat default for most users. Fast, reliable GPT models.
OpenClawwriteDeploy or connect official-only local and remote OpenClaw gateways, then map starter agents across your swarm by role, tag, or use case.
OpenRouterreadOne API key for a broad multi-provider model catalog through an OpenAI-compatible API.
OperatorreadCoordinates tasks, delegates work, and keeps the workspace moving.
OpsreadHandles deploys and infrastructure
ProbereadHeartbeat probe
PrototyperreadBuilds first, specs later.
RequestyreadOne API key for a broad multi-provider model catalog through an OpenAI-compatible gateway, with caching, failover, and cost controls.
ResearcherreadCollects facts, compares options, and produces structured findings.
ReviewerreadReviews plans and outputs for bugs, regressions, and quality gaps.
RexreadA helpful agent
Roomread
RouterreadA helpful assistant powered through OpenRouter.
SidekickreadA versatile assistant for everyday work, planning, and follow-through.
SparkreadA helpful assistant powered by Fireworks AI.
SwarmClawreadAI agent orchestration
SwarmyreadHelpful coding agent
Testread
TokenMixreadOne OpenAI-compatible API relay for Claude, OpenAI, Gemini, DeepSeek, Qwen, and other hosted models.
TriagerreadTriages inbound messages into urgent, reply-needed, and informational buckets.
Workerread
Writerread
areadTool A
a2areadA2A Protocol gateway
activityreadQuery activity feed events
agentsreadManage agents
approvalsreadList and resolve human-loop approvals
artifactsreadResolve evidence artifacts for runs, missions, and tasks
authreadAccess key auth helpers
autonomyreadInspect supervisor incidents and reflection output
breadTool B
browserreadControl a persistent browser profile. Supports low-level actions plus higher-level workflows like read_page, extract_links, extract_form_fields, extract_table, fill_form, submit_form, scroll_until, download_file, complete_web_task, profile, and reset_profile.
creadTool C
chatroom-policyreadConfigure chatroom delegation refusal policies
chatroomsreadManage multi-agent chatrooms
chatsreadManage agent chats and runtime controls
claude-skillsreadRead local Claude skills directory metadata
clawhubwriteBrowse and install ClawHub skills
config-versionsreadInspect and restore configuration version history
connector_message_toolwriteSend and manage outbound messages across chat platforms.
connectorsreadManage chat connectors
context_statusreadCheck token usage and context window limits.
context_summarizereadCompact conversation history to free up space.
cost-attributionreadAggregate LLM cost by billing-code tags
credentialsreadManage encrypted provider credentials
custom_media_senderwriteSend rendered media somewhere special.
cwd_checkread
daemonreadControl background daemon
delegatereadDelegate to a specialized backend (Claude, Codex, OpenCode, Gemini, Copilot, Droid, Cursor, Qwen) for code tasks: writing files, refactoring, debugging, code generation, and multi-file edits. Supports background jobs with action=status|list|wait|cancel.
delegation-jobsreadDelegation job status
deploy-repair-workflowwriteRepair deploy regressions in a stable order.
deploy-triagewriteTriage deploy issues in a fixed order.
deploy-verificationwriteVerify deploy blockers, config, and smoke checks.
deploy-workflow-learnedwriteAgent-scoped deploy workflow.
dirsreadDirectory listing and native picker
dispatch-helper.mdreadDispatch through manage_skills status.
documentsreadManage documents
echoread
edit_filewriteSurgically replace a specific string within a file.
emailwriteSend an email or check email configuration status. For sending: provide to, subject, and body. Optionally include html for rich formatting.
evalwriteRun agent evaluation scenarios
executewriteExecute a bash script. Supports curl, jq, awk, sed, grep, and 70+ Unix commands.
extension_creator_tooldestructiveCreate, read, edit, delete, or get the spec for writing new SwarmClaw extensions. Always call get_spec first to learn the correct format.
extensionsreadManage extensions and marketplace
external-agentsreadManage external agent runtimes
filesreadServe and manage local files
gatewaysreadManage named OpenClaw gateway profiles
generate_imagereadGenerate an image from a text prompt. The image is saved and a download link is returned. Use descriptive, detailed prompts for best results.
generic-notesreadStore notes.
githubreadGitHub operations
github-syncwriteStored GitHub flow.
github-sync.mdwriteSync GitHub issues into tasks.
goalsreadManage goal hierarchy
google-workspace-helperreadAutomate Google Workspace docs and sheets.
google_workspacewriteRun a Google Workspace CLI (
greetreadGreets
healthzreadPublic liveness probe
incident-triagewriteTriage incidents in a stable order.
ipreadGet local IP/port metadata
knowledgereadManage knowledge base entries
learned-skillsreadInspect agent-scoped learned skills
logsdestructiveRead or clear app logs
mailboxreadWork with email inboxes. Actions: status, list_messages, list_threads, search_messages, read_message, download_attachment, reply, wait_for_email.
manage_capabilitiesreadDiscover available built-in tools or external extensions, search marketplaces, or request access to a direct tool or extension id with action=
manage_platformreadUnified fallback tool for managing SwarmClaw resources when a more specific
manage_protocolsreadStructured orchestration workflows. Actions: list_templates, create_run (title, participantAgentIds, templateId or steps), run_status (runId), list_runs, run_action (runId, runAction: start|pause|resume|cancel), create_template (name, description, tags), run_events (runId).
mcp-registryreadBrowse the public SwarmDock MCP Registry
mcp-serversreadManage MCP server configurations
meeting-notesreadCapture meeting notes and follow-ups.
memoriesreadAlias of memory command group
memoryreadManage memory entries
memory-imagesreadFetch stored memory image assets
memory_getreadRead a specific memory entry by id or key after search, keeping context focused.
memory_searchreadSearch durable long-term memory for prior work, decisions, dates, people, preferences, or todos from earlier conversations. Prefer this before broader history tools.
memory_toolwriteAdvanced long-term memory system. Store and update canonical durable facts across conversations; store/update will merge matching memories and retire superseded variants. Search defaults to durable memories unless sources explicitly include archive or working.
memory_updatewriteUpdate or correct an existing durable memory when new information supersedes the old value.
missionsreadManage autonomous missions
monitor_toolwriteCreate durable waits that resume the agent when conditions trigger. Actions: create_watch, wait_until, wait_for_http, wait_for_file, wait_for_task, wait_for_webhook, wait_for_page_change, list_watches, get_watch, cancel_watch. For sys_info/ping/log tailing, use shell instead.
my_custom_toolreadDoes something useful
notificationsreadManage in-app notifications
openclawreadOpenClaw discovery, gateway control, and runtime APIs
openclaw_browserreadControl a browser through the OpenClaw CLI.
openclaw_nodesreadInteract with connected OpenClaw nodes/devices.
openclaw_workspacereadVersioning tools for the OpenClaw workspace.
operationsreadOperator triage and readiness summaries
other-agent-skillreadShould not leak.
perfreadInspect or control runtime perf tracing
pin_contextreadPin a fact, failed approach, blocker, or discovery to working memory so it survives context compaction and flows to subagents.
pingread
platformreadConsolidated platform tool. Use dotted action names:
portabilitywriteExport and import agent configurations
preview-serverreadManage preview dev servers
projectsreadManage projects
prompt-helper.mdreadGuidance-only workflow.
protocolsreadManage Structured Session runs and templates
providersreadManage providers and model overrides
read_filereadReads a file
replicatewriteRun AI models on Replicate. Actions: run (create and wait for prediction), get (check prediction status), cancel (stop a prediction), get_model (model details), search (find models), status (check config).
request_tool_accessreadAsk the user for access to an extension I don\
runswriteSession run queue/history
schedule_wakewriteSchedule a wake event (reminder) for yourself in this chatroom.
schedulesreadManage schedules
searchreadGlobal search across app resources
secretsreadManage reusable encrypted secrets
send_filewriteSend a file to the user in chat. Use the returned /api/uploads/... links exactly as provided.
sessions_toolreadManage sessions and check identity. Actions: identity (whoami), list, history, spawn, update.
settingswriteRead/update app settings
setupreadSetup and provider validation helpers
sharereadPublic share links for missions, skills, and sessions
shellwriteExecute commands and manage processes. Use for git, curl, long-lived servers, and other host CLI tools.
skill-suggestionsreadReview conversation-derived skill drafts
skillsreadManage reusable skills
soulsreadBrowse and manage soul library templates
spawn_subagentreadDelegate tasks to other agents.
swarmdockreadSwarmDock marketplace
swarmfeedreadSwarmFeed social network
system-statusreadLightweight system health summary
treadd
tasksreadManage task board items
test-hub-skillreadA ClawHub test skill.
tool1readMy cool tool
ttsreadText-to-speech endpoint
uploadwriteUpload raw file/blob
uploadsreadManage uploaded artifacts
usagereadUsage and cost summary
versionwriteVersion and update checks
walletsreadManage agent wallets
webreadUnified web access tool. Actions: search (web search), fetch/extract (read URL content), crawl (bounded same-origin crawl), api (raw HTTP request with method/headers/body).
web_crawlwriteCrawl a small set of pages starting from one URL. Same-origin by default, bounded by maxPages and maxDepth.
web_extractreadExtract readable content from a URL with title and source URL included.
web_fetchreadRead a specific URL and return readable page text.
web_searchreadSearch the web and return ranked results with URLs and snippets.
webhookswriteManage and trigger webhooks
whatsapp-voice-fallbackreadUse a fallback voice synthesis path for WhatsApp delivery.
whatsapp-voice-fallback-v2readRevised fallback.
workflow-statesreadManage customizable task workflow states
workspace-helperreadAutomate workspace docs.
workspacesreadManage logical workspaces (multi-workspace scaffolding)
04

Trust audit

BLOCKgrade D · trust 66/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryFAIL
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (10 observation(s))
Network
declared (17 observation(s))
Shell
declared (5 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (25)

HIGHInventory / provenance · inv.suspicious_name · CWE-1104
src/lib/skill-save-payload.ts
skill-save-payload.ts
Why it matters. member named after an attack tool
Fix. remove or justify
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/components/openclaw/openclaw-deploy-panel.tsx:1184
placeholder="~/.ssh/id_ed25519"
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/lib/server/session-tools/index.ts:204
'**/.ssh/id_*', '**/.env', '**/.env.local', '**/.gnupg/**',
Why it matters. touches a credential store
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
src/lib/server/connectors/email.ts:71
: { rejectUnauthorized: false, checkServerIdentity: () => undefined }
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
src/lib/server/session-tools/email.ts:107
const tlsSocket = tls.connect({ socket, host: cfg.host, rejectUnauthorized: false }, () => {
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
src/lib/server/session-tools/email.ts:153
socket = tls.connect({ ...connectOpts, rejectUnauthorized: false }, () => {
Why it matters. certificate verification is disabled
Fix. leave verification on
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
src/lib/server/untrusted-content.ts:6
{ code: 'credential_theft', re: /\b(?:api key|token|password|secret|credential)s?\b[\s\S]{0,40}\b(?:send|share|reveal|print|dump|exfiltrat)/i, note: 'asks for secrets or credentials' },
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
electron/main.ts:8
const DEV_URL_DEFAULT = 'http://127.0.0.1:3456'
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
electron/server-lifecycle.ts:72
const url = `http://127.0.0.1:${port}`
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
scripts/browser-e2e-smoke.ts:150
const baseUrl = `http://127.0.0.1:${port}`
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
scripts/sandbox-browser-entrypoint.sh:58
if curl -sS --max-time 1 "http://127.0.0.1:${CHROME_CDP_PORT}/json/version" >/dev/null; then
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
src/components/chatrooms/reaction-picker.tsx:40
'🐶', '🐱', '🐭', '🐹', '🐰', '🦊', '🐻', '🐼', '🐻❄️', '🐨',
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
src/components/chatrooms/reaction-picker.tsx:121
'❤️🔥', '❤️🩹', '❣️', '💕', '💞', '💓', '💗', '💖', '💘', '💝',
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
src/components/chatrooms/reaction-picker.tsx:133
'🚩', '🎌', '🏴', '🏳️', '🏳️🌈', '🏳️⚧️', '🏴☠️', '🇺🇸', '🇬🇧', '🇯🇵',
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
extension_creator_tool, logs
Why it matters. 2 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.eslint-baseline.json
.eslint-baseline.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.suspicious_name · CWE-1104
src/lib/skill-save-payload.test.ts
skill-save-payload.test.ts
Why it matters. member named after an attack tool
Fix. remove or justify
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
scripts/ensure-sandbox-browser-image.mjs:45
const hash = crypto.createHash('sha1')
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/lib/server/autonomy/supervisor-reflection.ts:290
outputHashes.add(crypto.createHash('sha1').update(output.slice(0, 500)).digest('hex').slice(0, 12))
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/lib/server/autonomy/supervisor-reflection.ts:1002
const signature = crypto.createHash('sha1')
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/lib/server/connectors/openclaw.ts:527
const textHash = crypto.createHash('sha1').update(text).digest('hex').slice(0, 16)
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/lib/server/eval/agent-regression.ts:217
return createHash('sha1').update(input).digest('hex').slice(0, 8)
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/app/api/approvals/route.test.ts:8
const repoRoot = path.resolve(path.dirname(new URL(import.meta.url).pathname), '../../../..')
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/app/api/clawhub/install/route.test.ts:8
const repoRoot = path.resolve(path.dirname(new URL(import.meta.url).pathname), '../../../../..')
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/app/api/mcp-servers/route.test.ts:19
'../../../lib/server/__fixtures__/fake-mcp-stdio-server.mjs',

Gates applied: no_behavioural_pass.

Audited 2026-09-28 · audit v0.4.1 · source sha 957c9e3d8e01full audit observations/trust-audit/mcp-server/swarmclawai__swarmclaw.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-28957c9e3d8e01BLOCKD66first audit
06

Questions

What is the SwarmClaw MCP server?

Open-source self-hosted AI agent runtime and multi-agent framework for autonomous agent swarms. Agent memory, MCP tools, schedules, delegation, and 23+ LLM providers (Claude, GPT, Gemini, OpenRouter, Ollama). A practical Claude Code and LangChain alternative.

What tools does SwarmClaw expose?

190 in total: 157 read-only, 31 that write, and 2 that can delete or overwrite (extension_creator_tool, logs). Every one is listed on this page with its risk.

Is SwarmClaw safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (66/100) and found 6 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does SwarmClaw need?

It reads ACCESS_KEY, COPILOT_GITHUB_TOKEN, CREDENTIAL_SECRET, ELEVENLABS_API_KEY, EXA_API_KEY, FACTORY_API_KEY, GEMINI_API_KEY, GH_TOKEN, GITHUB_PERSONAL_ACCESS_TOKEN, GITHUB_TOKEN, GOOGLE_API_KEY and OLLAMA_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does SwarmClaw run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @swarmclawai/swarmclaw at 1.9.40.

How current is this page?

The grade is for one exact copy of the source (957c9e3d8e01), read on 2026-09-28. The repository is watched and re-audited when it changes.

Advertisement