1Claw Vault
HSM-backed vault secrets for AI agents (JIT fetch) plus prompt-injection and threat scanning.
Verdict not yet evaluated for this tool. The hybrid eval runs adversarial cases first; coverage rolls out as the corpus expands (15 of 150 labels to graduation). Until a verdict is recorded, an agent should treat this tool as not-yet-cleared and fall back to its own checks. Method: hybrid eval, four-state verdict, honest limits.
Own this server? Screen its description →
ONECLAW_AGENT_API_KEYAgent API key (ocv_...). Exchanged for a short-lived JWT; auto-discovers agent ID and vault. Recommended for stdio.
ONECLAW_AGENT_IDOptional agent UUID when pinning identity (usually auto-discovered from the API key).
ONECLAW_VAULT_IDOptional vault UUID when the agent can access multiple vaults.
ONECLAW_BASE_URLVault API base URL (default https://api.1claw.xyz).
ONECLAW_LOCAL_ONLYSet to true for security-only mode (inspect_content only; no vault credentials).
Fresh data AI models lack: live prices, software versions, CVEs, service status & more.
Security tools for AI agents: scan MCP servers, validate HDP delegation chains, audit releases.
Provide AI-powered real-time analysis and intelligence on NPM packages, including security, depend…