‹ The Index

1Claw Vault

npm

HSM-backed vault secrets for AI agents (JIT fetch) plus prompt-injection and threat scanning.

Works with: Claude Code, Cursor, Claude Desktop, Codex CLI, Gemini CLI, Cline, Windsurf, VS Code

Category: AI & Agents — see all ranked ›

Install (Claude Code):

claude mcp add 1-law--ault -- npx -y @1claw/mcp
solid

“35 tools and every env var tabulated; no client config block or example call”

Security audit

scanned 2026-07-30

Every finding is shown in full. A licence adds the detail needed to act on it — which advisory, what the install script does, the version that fixes it.

No known advisoriesclearchecked against OSV for 0.41.4
Reads and writes files · Makes network requestsfrom declared dependencies
Can carry remote content into your agentunlock detail
No build provenanceno attestation — the published artifact cannot be traced to its source

1 finding here has detail behind a licence. You can see it exists above, free, permanently — Pro tells you what third-party content it can pull into your agent.

Unlock the fix — $6/mo ›or check your whole config free with npx tashan-cli doctor

npm ↗  ·  source ↗  ·  pkg:@1claw/mcp

Already running this? npx tashan-cli doctor checks your whole config against the Index — how it works ›