Search and run web scrapers from the CoreClaw Store to retrieve structured data through AI agents.
Do not connect
A critical issue was found. Do not connect this server as-is.
Scanned 26 days ago Due for re-check
A server can change after it's graded. Re-run the automated scan to refresh this report.
This grade is deterministic and reproducible: the same server surface always yields the same grade under a given algorithm version. It is a real automated assessment computed by the MCPGrade engine from what the probe actually observed — not a fabricated or opinion score. It is not a manual human pentest, so it can miss context-specific risks.
Every signal below was measured directly by the automated probe. The grade is derived only from evidence like this — nothing is assumed.
The coreclaw-mcp-server MCP server exposes 42 tools, focused primarily on database and network capabilities. Its published description reads: "Search and run web scrapers from the CoreClaw Store to retrieve structured data through AI agents". It communicates over Streamable HTTP using the 2025-06-18 protocol revision, and does not require authorization to connect. MCPGrade currently rates coreclaw-mcp-server F — a critical issue was found and the server should not be connected as-is. Its most notable findings include "Cross-tool shadowing" and "Cross-tool shadowing". This report is a deterministic, reproducible automated assessment: the same observed surface always yields the same grade under a given algorithm version, and it is refreshed as new scans arrive and free to read — but it is not a substitute for a manual human security review. Always re-check coreclaw-mcp-server's advertised tools, transport security, and authorization posture before connecting an autonomous agent or sharing sensitive context with it.
Add coreclaw-mcp-server to an MCP client using the endpoint below. Review the grade and findings above before granting an autonomous agent access.
MCP endpoint
https://mcp.coreclaw.com/mcpStreamable HTTP transport. This is the MCP endpoint, not a website — paste it into your MCP client server list rather than a browser.
Captured passively during the read-only scan. Click any value to find servers that match it.
The tools this server advertises via tools/list — names, purposes, and the parameters each accepts, exactly as enumerated read-only.
List CoreClaw proxy regions in English or Chinese. WHEN TO USE: Use when the user needs proxy country or region codes before running a worker, such as US, JP, DE, or Chinese localized names. 中文触发: 当用户
Search the public CoreClaw worker marketplace for ready-to-run workers. WHEN TO USE: Use when the user wants to find, discover, browse, or search CoreClaw scrapers/workers by keyword or site name. 中文触
List CoreClaw workers owned by the current user. WHEN TO USE: Use when the user wants their private/current-user workers, not the public marketplace. 中文触发: 当用户要在 CoreClaw 中查询、运行、重跑、停止、导出或查看对应 worker/r
Get detail for a CoreClaw worker. WHEN TO USE: Use before running a worker to inspect version, README, and parameters. 中文触发: 当用户要在 CoreClaw 中查询、运行、重跑、停止、导出或查看对应 worker/run/task 数据时使用。 WHEN NOT TO USE:
Get the public input JSON schema for a CoreClaw worker. WHEN TO USE: Use when the user wants to know required input fields or before composing run_worker input_json. 中文触发: 当用户要在 CoreClaw 中查询、运行、重跑、停止、
List saved CoreClaw worker tasks for the current user. WHEN TO USE: Use when the user wants saved tasks, scheduled presets, configured jobs, or task ids. 中文触发: 当用户要在 CoreClaw 中查询、运行、重跑、停止、导出或查看对应 work
Get detail for a specific saved CoreClaw worker task. WHEN TO USE: Use when the user wants to inspect a saved task's configuration, schedule, or input. 中文触发: 当用户要在 CoreClaw 中查询、运行、重跑、停止、导出或查看对应 worker
Get the input payload for a saved CoreClaw worker task. WHEN TO USE: Use when the user wants to inspect or copy a task's saved input parameters. 中文触发: 当用户要在 CoreClaw 中查询、运行、重跑、停止、导出或查看对应 worker/run/ta
Get the current user's CoreClaw account balance and traffic quota. WHEN TO USE: Use when the user asks for balance, remaining traffic, quota, billing state, or whether they can run jobs. 中文触发: 当用户要在 C
Create a new saved CoreClaw worker task with input and optional schedule. WHEN TO USE: Use when the user wants to save a worker configuration as a reusable, scheduled task. 中文触发: 当用户要在 CoreClaw 中查询、运行
Update a saved CoreClaw worker task's metadata and schedule. Partial update: omit fields to keep their current values. WHEN TO USE: Use when the user wants to change a task's title, description, or sc
Update the input payload for a saved CoreClaw worker task. WHEN TO USE: Use when the user wants to change a task's saved input parameters without modifying its title/schedule. 中文触发: 当用户要在 CoreClaw 中查询
Run a CoreClaw worker with an ad-hoc JSON input payload. WHEN TO USE: Use when the user wants to start, execute, scrape, crawl, or run a worker with specific input. 中文触发: 当用户要在 CoreClaw 中查询、运行、重跑、停止、导
Run a saved CoreClaw worker task. WHEN TO USE: Use when the user wants to execute a configured task rather than supply ad-hoc worker input. 中文触发: 当用户要在 CoreClaw 中查询、运行、重跑、停止、导出或查看对应 worker/run/task 数据
Run multiple CoreClaw workers in one call and return a per-item summary (run_slug, status, verdict). Serial by default; optional concurrency. WHEN TO USE: Use when accepting/validating many workers at
Submit a CoreClaw worker run to the Run Queue instead of executing immediately. WHEN TO USE: Use when the user wants to queue a run for later activation rather than start it right away. Returns a queu
List items in the CoreClaw Run Queue. WHEN TO USE: Use when the user wants to inspect queued runs, find a queue_ref, or check waiting/inactive items before activating or releasing. 中文触发: 当用户要在 CoreCla
Activate one or more waiting CoreClaw Run Queue items so they start executing. WHEN TO USE: Use when the user previously queued runs via queue_worker_run and now wants to start them. 中文触发: 当用户要在 CoreC
Release (remove) one or more CoreClaw Run Queue items so they never execute. WHEN TO USE: Use when the user no longer needs queued runs and wants to remove them in bulk. This is the batch version. 中文触
Release (remove) a single CoreClaw Run Queue item so it never executes. WHEN TO USE: Use when the user wants to remove one queued run by its queue_id. Same as release_run_queue_items but takes the que
List the current user's CoreClaw worker runs. WHEN TO USE: Use when the user wants run history, recent jobs, or to find a run_id by worker or status. 中文触发: 当用户要在 CoreClaw 中查询、运行、重跑、停止、导出或查看对应 worker/r
Get the current user's most recent CoreClaw worker run. WHEN TO USE: Use when the user says last run, latest job, most recent scrape, or asks what just happened. 中文触发: 当用户要在 CoreClaw 中查询、运行、重跑、停止、导出或查
Get detail for a specific CoreClaw worker run by run_id. WHEN TO USE: Use when the user gives a run id or wants status/cost/detail for a specific run. 中文触发: 当用户要在 CoreClaw 中查询、运行、重跑、停止、导出或查看对应 worker/
Poll a CoreClaw worker run until it reaches a terminal state (succeeded/failed/aborted) or the timeout elapses, then return the final status and optionally a result preview. WHEN TO USE: Use when run_
Verify a CoreClaw worker run produced real, usable data and return a structured PASS/NO_DATA/FAILED/ERROR_RECORD verdict. WHEN TO USE: Use after a run reaches a terminal state to get an acceptance ver
Get the most recent run for a specific CoreClaw worker. WHEN TO USE: Use when the user asks for the last run of a specific worker. 中文触发: 当用户要在 CoreClaw 中查询、运行、重跑、停止、导出或查看对应 worker/run/task 数据时使用。 WHEN
List paginated results from the current user's most recent CoreClaw run. WHEN TO USE: Use when the user wants to preview, inspect, or page through latest run output. 中文触发: 当用户要在 CoreClaw 中查询、运行、重跑、停止、
Export the current user's most recent CoreClaw run results. WHEN TO USE: Use when the user asks to download/export the latest run as CSV or JSON. 中文触发: 当用户要在 CoreClaw 中查询、运行、重跑、停止、导出或查看对应 worker/run/t
Get logs for the current user's most recent CoreClaw worker run. WHEN TO USE: Use when debugging why the latest run failed, stalled, or produced unexpected output. 中文触发: 当用户要在 CoreClaw 中查询、运行、重跑、停止、导出
List paginated results for a specific CoreClaw worker run. WHEN TO USE: Use when the user wants records/output rows from a known run id. 中文触发: 当用户要在 CoreClaw 中查询、运行、重跑、停止、导出或查看对应 worker/run/task 数据时使用
Export result data for a specific CoreClaw worker run. WHEN TO USE: Use when the user asks to download or save output from a known run as CSV or JSON. 中文触发: 当用户要在 CoreClaw 中查询、运行、重跑、停止、导出或查看对应 worker/
Get logs for a specific CoreClaw worker run, optionally filtered to lines matching error/traceback keywords. WHEN TO USE: Use to debug a known run id, especially failed, stalled, or suspicious runs. P
List paginated results from the most recent run of a specific CoreClaw worker. WHEN TO USE: Use when the user wants latest output rows for a known worker. 中文触发: 当用户要在 CoreClaw 中查询、运行、重跑、停止、导出或查看对应 wor
Export results from the most recent run of a specific CoreClaw worker. WHEN TO USE: Use when the user asks to download/export the latest output for a known worker. 中文触发: 当用户要在 CoreClaw 中查询、运行、重跑、停止、导出
Get logs for the most recent run of a specific CoreClaw worker. WHEN TO USE: Use when debugging the latest run for a specific worker. 中文触发: 当用户要在 CoreClaw 中查询、运行、重跑、停止、导出或查看对应 worker/run/task 数据时使用。 W
Rerun the current user's most recent CoreClaw worker run with the same saved inputs. WHEN TO USE: Use when the user says rerun last, retry latest, or do the previous scrape again. 中文触发: 当用户要在 CoreClaw
Rerun a specific CoreClaw worker run with the same saved inputs. WHEN TO USE: Use when the user wants to retry or repeat a known run id. 中文触发: 当用户要在 CoreClaw 中查询、运行、重跑、停止、导出或查看对应 worker/run/task 数据时使用
Rerun the most recent run for a specific CoreClaw worker. WHEN TO USE: Use when the user asks to retry or repeat the latest run for a known worker. 中文触发: 当用户要在 CoreClaw 中查询、运行、重跑、停止、导出或查看对应 worker/run
Abort the current user's most recent CoreClaw worker run. WHEN TO USE: Use when the user wants to stop or cancel the last running job. 中文触发: 当用户要在 CoreClaw 中查询、运行、重跑、停止、导出或查看对应 worker/run/task 数据时使用。
Abort a specific CoreClaw worker run by run_id. WHEN TO USE: Use when the user wants to cancel a known running run. 中文触发: 当用户要在 CoreClaw 中查询、运行、重跑、停止、导出或查看对应 worker/run/task 数据时使用。 WHEN NOT TO USE: Do
Abort the most recent run for a specific CoreClaw worker. WHEN TO USE: Use when the user wants to cancel the latest active run of a known worker. 中文触发: 当用户要在 CoreClaw 中查询、运行、重跑、停止、导出或查看对应 worker/run/t
Delete a saved CoreClaw worker task. WHEN TO USE: Use when the user wants to permanently remove a saved task. 中文触发: 当用户要在 CoreClaw 中查询、运行、重跑、停止、导出或查看对应 worker/run/task 数据时使用。 WHEN NOT TO USE: Do not u
Sorted worst-first. Each finding shows its severity, what it means, its OWASP MCP Top-10 mapping, and a recommended fix — the check id links to the exact methodology row that produced it.
tool: list_proxy_regions
A tool description tries to alter the model’s use of another tool.
OW: Call before run_worker when the worker input schema asks for proxy_regRecommendationDescriptions must describe only their own tool.
tool: list_store_workers
A tool description tries to alter the model’s use of another tool.
input_schema or get_worker before run_worker.RecommendationDescriptions must describe only their own tool.
tool: list_workers
A tool description tries to alter the model’s use of another tool.
OW: Follow with get_worker, get_worker_input_schema, run_worker, or workerRecommendationDescriptions must describe only their own tool.
tool: get_worker
A tool description tries to alter the model’s use of another tool.
OW: Follow with get_worker_input_schema and then run_worker.RecommendationDescriptions must describe only their own tool.
tool: get_worker_input_schema
A tool description tries to alter the model’s use of another tool.
efore composing run_worker input_json. 中文触发: 当用户要在 CoreClaw 中查询、运行、重跑、停止、导RecommendationDescriptions must describe only their own tool.
tool: list_worker_tasks
A tool description tries to alter the model’s use of another tool.
OW: Follow with run_worker_task using worker_task_id.RecommendationDescriptions must describe only their own tool.
tool: get_worker_task
A tool description tries to alter the model’s use of another tool.
OW: Follow with update_worker_task, update_worker_task_input, run_worker_task, orRecommendationDescriptions must describe only their own tool.
tool: get_worker_task_input
A tool description tries to alter the model’s use of another tool.
OW: Follow with update_worker_task_input or run_worker_task.RecommendationDescriptions must describe only their own tool.
tool: get_account_info
A tool description tries to alter the model’s use of another tool.
reflight before run_worker.RecommendationDescriptions must describe only their own tool.
tool: create_worker_task
A tool description tries to alter the model’s use of another tool.
OW: Follow with run_worker_task using the returned worker_task_id.RecommendationDescriptions must describe only their own tool.
tool: update_worker_task
A tool description tries to alter the model’s use of another tool.
LOW: Call after get_worker_task to confirm current settings. Use update_worker_RecommendationDescriptions must describe only their own tool.
tool: update_worker_task_input
A tool description tries to alter the model’s use of another tool.
LOW: Call after get_worker_task_input to confirm the current input. Then use run_workRecommendationDescriptions must describe only their own tool.
tool: run_worker
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "callback_url"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: run_worker
A tool description tries to alter the model’s use of another tool.
WORKFLOW: Call get_worker_input_schema first, then run_worker, then get_worker_run orRecommendationDescriptions must describe only their own tool.
tool: run_worker_task
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "callback_url"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: run_worker_task
A tool description tries to alter the model’s use of another tool.
t_worker_run or get_last_worker_run, then result/export tools.RecommendationDescriptions must describe only their own tool.
tool: run_workers_batch
A tool description tries to alter the model’s use of another tool.
LOW: Call after list_store_workers/list_workers + get_worker_input_schema for eachRecommendationDescriptions must describe only their own tool.
tool: queue_worker_run
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "callback_url"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: queue_worker_run
A tool description tries to alter the model’s use of another tool.
nstead of executing immediately. WHEN TO USE: Use when the user wants toRecommendationDescriptions must describe only their own tool.
tool: list_run_queue_items
A tool description tries to alter the model’s use of another tool.
OW: Follow with activate_run_queue_items to start waiting items, or release_run_queue_itRecommendationDescriptions must describe only their own tool.
tool: activate_run_queue_items
A tool description tries to alter the model’s use of another tool.
queued runs via queue_worker_run and now wants to start them. 中文触发: 当用户要在 CoreClRecommendationDescriptions must describe only their own tool.
tool: release_run_queue_items
A tool description tries to alter the model’s use of another tool.
LOW: Call after list_run_queue_items to collect the queue_refs to release.RecommendationDescriptions must describe only their own tool.
tool: release_run_queue_item
A tool description tries to alter the model’s use of another tool.
LOW: Call after list_run_queue_items to confirm the queue_id.RecommendationDescriptions must describe only their own tool.
tool: list_worker_runs
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
user wants run history, recent jobs, or to find a run_id by worker orRecommendationRemove side-channel parameters; constrain tool inputs.
tool: list_worker_runs
A tool description tries to alter the model’s use of another tool.
OW: Follow with get_worker_run, list_worker_run_results, export_worker_run_resRecommendationDescriptions must describe only their own tool.
tool: get_last_worker_run
A tool description tries to alter the model’s use of another tool.
OW: Follow with list_last_worker_run_results, export_last_worker_run_results, get_last_workeRecommendationDescriptions must describe only their own tool.
tool: poll_run
A tool description tries to alter the model’s use of another tool.
O USE: Use when run_worker returned an async run and the caller wants to wRecommendationDescriptions must describe only their own tool.
tool: verify_run
A tool description tries to alter the model’s use of another tool.
ter poll_run or get_worker_run shows a terminal state. Use get_worker_run_logRecommendationDescriptions must describe only their own tool.
tool: list_last_worker_run_results
A tool description tries to alter the model’s use of another tool.
LOW: Call after get_last_worker_run shows status succeeded; use export_last_worker_RecommendationDescriptions must describe only their own tool.
tool: export_last_worker_run_results
A tool description tries to alter the model’s use of another tool.
LOW: Call after get_last_worker_run shows status succeeded.RecommendationDescriptions must describe only their own tool.
tool: get_last_worker_run_log
A tool description tries to alter the model’s use of another tool.
LOW: Call after get_last_worker_run, especially for failed or running states.RecommendationDescriptions must describe only their own tool.
tool: list_worker_run_results
A tool description tries to alter the model’s use of another tool.
LOW: Call after get_worker_run shows status succeeded; use export_worker_run_rRecommendationDescriptions must describe only their own tool.
tool: export_worker_run_results
A tool description tries to alter the model’s use of another tool.
LOW: Call after get_worker_run shows status succeeded.RecommendationDescriptions must describe only their own tool.
tool: get_worker_run_log
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "context_lines"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: get_worker_run_log
A tool description tries to alter the model’s use of another tool.
tead of reading the whole log; the raw log often has only a few system linRecommendationDescriptions must describe only their own tool.
tool: list_worker_last_run_results
A tool description tries to alter the model’s use of another tool.
LOW: Call after get_worker_last_run shows status succeeded; use export_worker_last_RecommendationDescriptions must describe only their own tool.
tool: export_worker_last_run_results
A tool description tries to alter the model’s use of another tool.
LOW: Call after get_worker_last_run shows status succeeded.RecommendationDescriptions must describe only their own tool.
tool: get_worker_last_run_log
A tool description tries to alter the model’s use of another tool.
LOW: Call after get_worker_last_run when status or output needs explanation.RecommendationDescriptions must describe only their own tool.
tool: rerun_last_worker_run
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "callback_url"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: rerun_last_worker_run
A tool description tries to alter the model’s use of another tool.
OW: Follow with get_last_worker_run or list_last_worker_run_results depending on isRecommendationDescriptions must describe only their own tool.
tool: rerun_worker_run
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "callback_url"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: rerun_worker_run
A tool description tries to alter the model’s use of another tool.
OW: Follow with get_worker_run or list_worker_run_results for the new run.RecommendationDescriptions must describe only their own tool.
tool: rerun_worker_last_run
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "callback_url"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: rerun_worker_last_run
A tool description tries to alter the model’s use of another tool.
OW: Follow with get_worker_last_run or list_worker_last_run_results.RecommendationDescriptions must describe only their own tool.
tool: abort_last_worker_run
A tool description tries to alter the model’s use of another tool.
LOW: Call after get_last_worker_run confirms the last run is still active.RecommendationDescriptions must describe only their own tool.
tool: abort_worker_run
A tool description tries to alter the model’s use of another tool.
LOW: Call after get_worker_run confirms status is ready or running.RecommendationDescriptions must describe only their own tool.
tool: abort_worker_last_run
A tool description tries to alter the model’s use of another tool.
LOW: Call after get_worker_last_run confirms the run is active.RecommendationDescriptions must describe only their own tool.
tool: delete_worker_task
A tool description tries to alter the model’s use of another tool.
LOW: Call after list_worker_tasks or get_worker_task confirms the task exists.RecommendationDescriptions must describe only their own tool.
tool: (server instructions)
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
ers may provide api-key, X-API-Key, or Authorization: Bearer <token>; tRecommendationRemove side-channel parameters; constrain tool inputs.
tool: (server instructions)
A tool description tries to alter the model’s use of another tool.
's workers. Use list_proxy_regions when a worker input asks for a proxy region. 2.RecommendationDescriptions must describe only their own tool.
The server accepts tool enumeration (and likely invocation) with no authentication.
RecommendationRequire OAuth 2.1 authorization for any server exposing non-public tools.
tool: run_worker
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: run_worker_task
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: run_workers_batch
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: queue_worker_run
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: release_run_queue_items
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: release_run_queue_item
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: rerun_last_worker_run
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: rerun_worker_run
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: rerun_worker_last_run
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: delete_worker_task
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
Vantaj uptime monitoring via MCP — manage monitors, heartbeats, incidents, and status pages.
Unified gateway to Algeria's TKAWEN ecosystem: commerce, certification, and AI tools.
Provides access to the Cohereon Doctrine AI safety framework with governance components, tiered access, and agent onboarding.
Agentic rails for complex workflows with receipts, fees, and MCP tool access.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.