MCP Security Audit
github/awesome-copilot
Audit MCP (Model Context Protocol) server configurations for security issues.
Installs or refreshes OneCLI as the gateway provider for NanoClaw, copying the adapter files, registering the provider and running the setup script.
$ npx skills add nanocoai/nanoclaw --skill add-onecli -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install nanocoai/nanoclaw add-onecli --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/nanocoai/nanoclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/add-onecli .claude/skills/add-onecli && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "add-onecli" agent skill from https://github.com/nanocoai/nanoclaw/tree/main/.claude/skills/add-onecli into .claude/skills/add-onecli/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "add-onecli", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/nanocoai/nanoclaw/tree/main/.claude/skills/add-onecliType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add nanocoai/nanoclaw --skill add-onecli -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install nanocoai/nanoclaw add-onecli --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nanocoai/nanoclaw.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/add-onecli .agents/skills/add-onecli && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "add-onecli" agent skill from https://github.com/nanocoai/nanoclaw/tree/main/.claude/skills/add-onecli into .agents/skills/add-onecli/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "add-onecli", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add nanocoai/nanoclaw --skill add-onecli -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install nanocoai/nanoclaw add-onecli --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nanocoai/nanoclaw.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/add-onecli .cursor/skills/add-onecli && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "add-onecli" agent skill from https://github.com/nanocoai/nanoclaw/tree/main/.claude/skills/add-onecli into .cursor/skills/add-onecli/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "add-onecli", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/nanocoai/nanoclaw.git --path .claude/skills/add-onecli--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add nanocoai/nanoclaw --skill add-onecli -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install nanocoai/nanoclaw add-onecli --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nanocoai/nanoclaw.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/add-onecli .gemini/skills/add-onecli && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "add-onecli" agent skill from https://github.com/nanocoai/nanoclaw/tree/main/.claude/skills/add-onecli into .gemini/skills/add-onecli/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "add-onecli", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install nanocoai/nanoclaw add-onecliInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add nanocoai/nanoclaw --skill add-onecli -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/nanocoai/nanoclaw.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/add-onecli .github/skills/add-onecli && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "add-onecli" agent skill from https://github.com/nanocoai/nanoclaw/tree/main/.claude/skills/add-onecli into .github/skills/add-onecli/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "add-onecli", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add nanocoai/nanoclaw --skill add-onecli -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install nanocoai/nanoclaw add-onecli --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nanocoai/nanoclaw.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/add-onecli .opencode/skills/add-onecli && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "add-onecli" agent skill from https://github.com/nanocoai/nanoclaw/tree/main/.claude/skills/add-onecli into .opencode/skills/add-onecli/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "add-onecli", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
add-onecliInstalls or refreshes OneCLI as the gateway provider for NanoClaw, copying the adapter files, registering the provider and running the setup script.
This skill owns the whole OneCLI integration for NanoClaw, while NanoClaw core supplies the generic gateway seam and the approval workflow. It copies the package's native adapter, tests and agent guidance into their normal paths, registers the provider with a single import line, and installs a pinned OneCLI SDK with pnpm.
A setup script reuses a healthy existing gateway, installs the pinned local gateway when none exists, or connects to a remote one through NANOCLAW_ONECLI_API_HOST and NANOCLAW_ONECLI_API_TOKEN. Only the gateway version pinned in the skill's versions.json is supported, which is 1.42.0 today, and 1.43 and later are not supported because they remove the secret-assignment API. Setup does not check an existing gateway's version, so an upgrade guide is included.
For provider credentials, such as those stored by /add-opencode, the group's OneCLI agent must be granted access to the secret: read the existing assignments, merge in the new secret ID and verify with onecli agents secrets, because set-secrets replaces assignments. Keys never go in .env, command arguments or the container environment. A removal guide and a ChatGPT OAuth refresh reference are included.
Read from SKILL.md and the folder at commit 66f0823. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 3 files in scripts/ (TypeScript, from the files we listed), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
NANOCLAW_ONECLI_API_TOKENONECLI_API_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
NanoClaw OneCLI Gateway Installer loads about 1.1k tokens when it runs, and up to ~1.3k if it reads all its reference files. Until then it costs about 67 tokens; SKILL.md has 357 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
a key in `.env`, command arguments, or the container environment.Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from nanocoai/nanoclaw at commit 66f0823, republished under its MIT licence (© nanocoai). 357 words, ~1,050 tokens.
.claude/skills/add-onecli/SKILL.md (or your agent's skills folder). This skill also uses 22 other files; get the full folder from GitHub.This skill owns the full OneCLI integration. NanoClaw core supplies the generic gateway seam and existing skill engine.
Copy the package's native adapter, tests, and agent guidance into their normal NanoClaw paths. NanoClaw core owns the approval workflow.
payload/src/gateway-providers/onecli-files.ts -> src/gateway-providers/onecli-files.ts
payload/src/gateway-providers/onecli-files.test.ts -> src/gateway-providers/onecli-files.test.ts
payload/src/gateway-providers/onecli.ts -> src/gateway-providers/onecli.ts
payload/src/gateway-providers/onecli.test.ts -> src/gateway-providers/onecli.test.ts
payload/src/gateway-providers/onecli-install.test.ts -> src/gateway-providers/onecli-install.test.ts
payload/container/skills/onecli-gateway/SKILL.md -> container/skills/onecli-gateway/SKILL.md
payload/container/skills/onecli-gateway/instructions.md -> container/skills/onecli-gateway/instructions.md
payload/docs/onecli-upgrades.md -> docs/onecli-upgrades.mdThe provider file makes the only product registration call. It translates OneCLI sessions and native approval events into the generic contract.
import './onecli.js';@onecli-sh/sdk@2.2.1The setup script safely reuses a healthy existing installation, installs the pinned local gateway when absent, or uses NANOCLAW_ONECLI_API_HOST and NANOCLAW_ONECLI_API_TOKEN for a remote gateway.
This integration supports exactly the gateway version pinned in .claude/skills/add-onecli/versions.json (onecli-gateway, today 1.42.0; not the versions.json at the project root). OneCLI 1.43 and later remove the agent secret-assignment API used below, so 1.43+ is not supported for now. Setup reuses an existing gateway without checking its version: follow Upgrading the OneCLI gateway to check it and to move it to the pin. The CLI (onecli-cli) and SDK (onecli-sdk) have their own pins.
pnpm exec tsx .claude/skills/add-onecli/scripts/setup.tsProvider skills such as /add-opencode store model credentials here through the
gateway seam. OneCLI does not grant them automatically: grant the group's OneCLI
agent access to the chosen secret. Read its existing secret assignments first and
merge the new secret ID into that list, because onecli agents set-secrets
replaces assignments. Verify the result with onecli agents secrets. Do not put
a key in .env, command arguments, or the container environment.
ONECLI_URL and ONECLI_API_KEY.pnpm run buildpnpm exec vitest run src/gateway-providers/onecli-files.test.ts src/gateway-providers/onecli-install.test.ts src/gateway-providers/onecli.test.ts src/gateway-providers/gateway-provider-registry.test.ts src/gateway-approval-coordinator.test.tsThe setup consumer writes NANOCLAW_GATEWAY_PROVIDER=onecli only after every directive above succeeds. Claude authentication is then completed through scripts/auth.ts; credentials never enter an agent container.
During an atomic NanoClaw upgrade, scripts/detect.ts identifies an older implicit OneCLI installation so the generic updater can preserve that choice before the service restarts.
© nanocoai, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 22 other files (scripts, references) in .claude/skills/add-onecli of nanocoai/nanoclaw.
Open the folder on GitHubat commit 66f0823
NanoClaw OneCLI Gateway Installer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| NanoClaw OneCLI Gateway Installer this skillnanocoai/nanoclaw | 31k | — | ~1.1k | Automated safety check: Notes | MIT | |
| MCP Security Auditgithub/awesome-copilot | 40k | — | ~3.1k | Automated safety check: Pass | MIT | |
| Daytona Sandbox Operationsdifferent-ai/openwork | 24k | — | ~917 | Automated safety check: Pass | Custom licence | |
| Dotenvx Secretskortix-ai/suna | 20k | — | ~4.2k | Automated safety check: Notes | Custom licence | |
| MCP Security Auditboshi-xixixi/TraeSkill | 275 | — | ~2.2k | Automated safety check: Pass | MIT | |
| Warp GUI to Agent CLI Migrationwarpdotdev/warp | 65k | 1 repos | ~2.1k | Automated safety check: Pass | AGPL-3.0 |
github/awesome-copilot
Audit MCP (Model Context Protocol) server configurations for security issues.
different-ai/openwork
Covers Daytona CLI setup, sandbox debugging, keeping a sandbox alive and which credentials the CLI uses, for when Daytona itself is the problem rather than the tests.
kortix-ai/suna
How this repo manages API secrets and the four local-run environments (local/dev/staging/prod).
boshi-xixixi/TraeSkill
Audit MCP (Model Context Protocol) server configurations for security issues.
warpdotdev/warp
Migrates the compatible subset of settings and global file-based MCP servers from the Warp desktop app into Warp Agent CLI without exposing credentials or state.
Core-Mate/OpenGUI
Installs and verifies the latest stable OpenGUI release in a DeepSeek Harness web profile on macOS without disturbing existing plugins or settings.
nanocoai/nanoclaw
Installs or refreshes Iron Proxy and its Iron Control web console for NanoClaw, with a local Docker setup, database, credentials and a human approval bridge.
nanocoai/nanoclaw
Drives a web browser from the shell with the agent-browser CLI: open pages, read an element snapshot, click and fill by reference, grab text and screenshots.
nanocoai/nanoclaw
Guides a conversational migration from an OpenClaw install to NanoClaw v2, carrying over identity, channel credentials, scheduled tasks and workspace files.
nanocoai/nanoclaw
Wires up an additional phone number onto an already-installed Dial channel, so one NanoClaw install answers SMS and AI voice calls on more than one line.
nanocoai/nanoclaw
Adds a persistent wiki knowledge base to a NanoClaw group following Karpathy's LLM Wiki pattern, with folders, a tailored container skill and a CLAUDE.md section.
nanocoai/nanoclaw
Routes a NanoClaw agent group to a local Ollama model instead of the Anthropic API, using environment overrides and an optional block on Anthropic hosts.
Works with
Categories
Installs or refreshes OneCLI as the gateway provider for NanoClaw, copying the adapter files, registering the provider and running the setup script. This skill owns the whole OneCLI integration for NanoClaw, while NanoClaw core supplies the generic gateway seam and the approval workflow. It copies the package's native adapter, tests and agent guidance into their normal paths, registers the provider with a single import line, and installs a pinned OneCLI SDK with pnpm.
NanoClaw OneCLI Gateway Installer fits situations like: setting up NanoClaw with OneCLI as its gateway provider; migrating an existing OneCLI-backed install to the gateway seam; restoring the OneCLI runtime, approval bridge or agent guidance from the in-tree package.
Run `npx skills add nanocoai/nanoclaw --skill add-onecli -a claude-code`. Or copy the skill folder (.claude/skills/add-onecli in nanocoai/nanoclaw) into .claude/skills/add-onecli in your project. Claude Code loads it when a task matches its description.
Run `npx skills add nanocoai/nanoclaw --skill add-onecli -a codex`. Or copy the skill folder (.claude/skills/add-onecli in nanocoai/nanoclaw) into .agents/skills/add-onecli in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add nanocoai/nanoclaw --skill add-onecli -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/add-onecli, .gemini/skills/add-onecli, .github/skills/add-onecli and .opencode/skills/add-onecli in your project.
Going by SKILL.md and its folder, NanoClaw OneCLI Gateway Installer needs TypeScript for the scripts in its folder and credentials named NANOCLAW_ONECLI_API_TOKEN and ONECLI_API_KEY. Our summary lists: A NanoClaw checkout; pnpm and Node.js; For a remote gateway, its API host and token.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
NanoClaw OneCLI Gateway Installer is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.1k tokens (SKILL.md is roughly 4.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 289 tokens, read only when the agent opens those files.
Skills that share tags, products or a category with NanoClaw OneCLI Gateway Installer: MCP Security Audit (github/awesome-copilot, 40k stars), Daytona Sandbox Operations (different-ai/openwork, 24k stars), Dotenvx Secrets (kortix-ai/suna, 20k stars) and MCP Security Audit (boshi-xixixi/TraeSkill, 275 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
nanocoai (a GitHub organization) maintains it in nanocoai/nanoclaw, which has 30,897 GitHub stars. The repository holds 59 skills in this directory. The repository was last updated on October 6, 2026.
Source: nanocoai/nanoclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.