Dashclaw runs on your own machine — the client starts it, so there is no endpoint to ping. 133 installs a week from npm. Last commit 17 Sep 2026.
Policy checks, approvals, records, and governed HTTP capabilities for unattended agents.
We read the source, 23 h ago · rules 3dff92dd89df
Things with no honest explanation: a promise that contradicts the code, code that runs at install time while hiding what it does, data leaving the machine.
rm -rf'd a node_modules I actually needed for a different
What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.
этот файл ставится пользователю, но в репозитории его нет
env_path = os.path.join(current, fname)
subprocess.run(
execFile(
shell=True,
"secrets": ["**/secrets/**", "**/.env", "**/.env.*", "**/*.pem", "**/id_rsa*", "**/*.key", "app/secrets/**"],
env = dict(os.environ)
const TELEGRAM_API_BASE = 'https://api.telegram.org';
Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.
Code changes quietly between releases, and nobody reads the diff of a dependency. We do, on every release — watch Dashclaw and you get told the day something new turns up.
This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.
claude mcp add dashclaw -- npx -y @dashclaw/mcp-server
{
"mcpServers": {
"dashclaw": {
"args": [
"-y",
"@dashclaw/mcp-server"
],
"command": "npx"
}
}
}
[mcp_servers.dashclaw]
command = "npx"
args = ["-y", "@dashclaw/mcp-server"]
{
"mcpServers": {
"dashclaw": {
"args": [
"-y",
"@dashclaw/mcp-server"
],
"command": "npx"
}
}
}
{
"mcpServers": {
"dashclaw": {
"args": [
"-y",
"@dashclaw/mcp-server"
],
"command": "npx"
}
}
}
This one needs environment variables set before it will start:
DASHCLAW_URL (Base URL of your DashClaw instance (e.g. https://your-app.vercel.app)), DASHCLAW_API_KEY (DashClaw workspace API key (oc_live_...)), DASHCLAW_AGENT_ID (Optional agent identifier used to attribute governed actions).
The author declared them in the registry entry; get the values from the project itself.
Governed execution cells for AI agents: Docker/K8s sandboxes with policy, audit, and approvals.
Governed USDC wallet for AI agents — policy gates, spending caps, and Ed25519-signed receipts.
Discover admitted MERXAT products and check capabilities; payment governed server-side.
Watchdog for unattended AI agents: alerts, evidence checks and a verifiable proof per run.
Git-native policy layer for AI agents: check_action verdicts against rules approved via PR.
Real-time agentic newsfeed for MCP tools and capabilities
Unified MCP server for AgenticLens and Agentic Chaos capabilities.
Policy-based governance for AI agent tool calls. YAML policy, approval gates, audit logging.
Answers built from our own checks of this server.