AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
Crawler Summary
Cryptographic security layer for CrewAI MCP tool calls. Message signing, replay protection, tool hash-pinning. crewai-mcps Cryptographic security layer for CrewAI MCP tool calls. crewai-mcps adds message signing, nonce-based replay protection, and tool definition pinning to CrewAI's Model Context Protocol (MCP) integrations. It addresses specific risks from the $1: | OWASP MCP Risk | Coverage | What crewai-mcps does | |---|---|---| | **MCP-01: Tool Poisoning** | Full | Pins tool definitions at discovery; blocks execution if d Capability contract not published. No trust telemetry is available yet. Last updated 10/9/2026.
Freshness
Last checked 10/9/2026
Best For
crewai-mcps is best for crewai, multi-agent workflows where OpenClaw compatibility matters.
Not Ideal For
Contract metadata is missing or unavailable for deterministic execution.
Evidence Sources Checked
editorial-content, GITHUB REPOS, runtime-metrics, public facts pack
Cryptographic security layer for CrewAI MCP tool calls. Message signing, replay protection, tool hash-pinning. crewai-mcps Cryptographic security layer for CrewAI MCP tool calls. crewai-mcps adds message signing, nonce-based replay protection, and tool definition pinning to CrewAI's Model Context Protocol (MCP) integrations. It addresses specific risks from the $1: | OWASP MCP Risk | Coverage | What crewai-mcps does | |---|---|---| | **MCP-01: Tool Poisoning** | Full | Pins tool definitions at discovery; blocks execution if d
Public facts
4
Change events
1
Artifacts
0
Freshness
Oct 9, 2026
Capability contract not published. No trust telemetry is available yet. Last updated 10/9/2026.
Trust score
Unknown
Compatibility
OpenClaw
Freshness
Oct 9, 2026
Vendor
Razashariff
Artifacts
0
Benchmarks
0
Last release
Unpublished
Key links, install path, and a quick operational read before the deeper crawl record.
Summary
Capability contract not published. No trust telemetry is available yet. Last updated 10/9/2026.
Setup snapshot
Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.
Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Everything public we have scraped or crawled about this agent, grouped by evidence type with provenance.
Vendor
Razashariff
Protocol compatibility
OpenClaw
Handshake status
UNKNOWN
Crawlable docs
6 indexed pages on the official domain
Merged public release, docs, artifact, benchmark, pricing, and trust refresh events.
Extracted files, examples, snippets, parameters, dependencies, permissions, and artifact metadata.
Extracted files
0
Examples
6
Snippets
0
Languages
python
bash
pip install crewai-mcps
bash
pip install 'crewai-mcps[crewai]'
python
from crewai import Agent, Task, Crew
from crewai.mcp import MCPServerAdapter
from crewai_mcps import SecureMCPTool, AuditTrail
# Optional: audit trail for compliance
audit = AuditTrail()
# Zero config -- keys generated automatically
secure = SecureMCPTool(audit_trail=audit)
server_params = {
"url": "http://localhost:8001/mcp",
"transport": "streamable-http",
}
with MCPServerAdapter(server_params) as tools:
# One line to add security
secured_tools = secure.wrap_tools(tools)
agent = Agent(
role="Analyst",
goal="Perform secure analysis",
backstory="All tool calls are cryptographically signed.",
tools=secured_tools,
)
task = Task(
description="List available files.",
expected_output="A file listing.",
agent=agent,
)
crew = Crew(agents=[agent], tasks=[task])
result = crew.kickoff()
# Review what happened
print(audit.summary())
audit.export_json("audit.json")python
from crewai_mcps import SecureMCPTool, install_crewai_hooks secure = SecureMCPTool() cleanup = install_crewai_hooks(secure) # All tool calls are now signed automatically # ... run your crew ... cleanup() # Remove hooks when done
python
secure = SecureMCPTool()
# Sign a call manually
envelope = secure.sign_call("search", {"query": "test"})
# => {'nonce': '...', 'timestamp': '...', 'signature': '...', 'tool_name': 'search'}python
from crewai_mcps import NonceTracker tracker = NonceTracker(max_age_seconds=300) nonce = tracker.generate() # First use: OK tracker.check_and_consume(nonce) # True # Replay attempt: blocked tracker.check_and_consume(nonce) # False
Full documentation captured from public sources, including the complete README when available.
Docs source
GITHUB REPOS
Editorial quality
ready
Cryptographic security layer for CrewAI MCP tool calls. Message signing, replay protection, tool hash-pinning. crewai-mcps Cryptographic security layer for CrewAI MCP tool calls. crewai-mcps adds message signing, nonce-based replay protection, and tool definition pinning to CrewAI's Model Context Protocol (MCP) integrations. It addresses specific risks from the $1: | OWASP MCP Risk | Coverage | What crewai-mcps does | |---|---|---| | **MCP-01: Tool Poisoning** | Full | Pins tool definitions at discovery; blocks execution if d
Cryptographic security layer for CrewAI MCP tool calls.
crewai-mcps adds message signing, nonce-based replay protection, and tool definition pinning to CrewAI's Model Context Protocol (MCP) integrations. It addresses specific risks from the OWASP MCP Top 10:
| OWASP MCP Risk | Coverage | What crewai-mcps does |
|---|---|---|
| MCP-01: Tool Poisoning | Full | Pins tool definitions at discovery; blocks execution if definition changes |
| MCP-04: Tool Rug Pulls | Full | Hashes tool schemas on first contact; any mutation raises ToolIntegrityError |
| MCP-08: Logging Gaps | Full | Structured audit trail with sequence numbers, timestamps, and exportable JSON |
| MCP-10: Lack of Integrity | Full | Cryptographic signatures on canonical JSON payloads; tampered arguments fail verification |
| Replay Attacks | Full | Every call carries a unique nonce with configurable TTL; duplicates are rejected |
MCP-02 (permissions), MCP-06 (resource injection), MCP-07 (auth), and MCP-09 (resource abuse) are outside the scope of this package -- they require policy-layer enforcement. See ELIDA for behavioural-layer coverage of all 10.
pip install crewai-mcps
With CrewAI:
pip install 'crewai-mcps[crewai]'
from crewai import Agent, Task, Crew
from crewai.mcp import MCPServerAdapter
from crewai_mcps import SecureMCPTool, AuditTrail
# Optional: audit trail for compliance
audit = AuditTrail()
# Zero config -- keys generated automatically
secure = SecureMCPTool(audit_trail=audit)
server_params = {
"url": "http://localhost:8001/mcp",
"transport": "streamable-http",
}
with MCPServerAdapter(server_params) as tools:
# One line to add security
secured_tools = secure.wrap_tools(tools)
agent = Agent(
role="Analyst",
goal="Perform secure analysis",
backstory="All tool calls are cryptographically signed.",
tools=secured_tools,
)
task = Task(
description="List available files.",
expected_output="A file listing.",
agent=agent,
)
crew = Crew(agents=[agent], tasks=[task])
result = crew.kickoff()
# Review what happened
print(audit.summary())
audit.export_json("audit.json")
from crewai_mcps import SecureMCPTool, install_crewai_hooks
secure = SecureMCPTool()
cleanup = install_crewai_hooks(secure)
# All tool calls are now signed automatically
# ... run your crew ...
cleanup() # Remove hooks when done
Every tool call is signed with an automatically generated key pair. The signature covers the canonical JSON of the tool name, arguments, nonce, and timestamp. Any tampering with the arguments invalidates the signature.
secure = SecureMCPTool()
# Sign a call manually
envelope = secure.sign_call("search", {"query": "test"})
# => {'nonce': '...', 'timestamp': '...', 'signature': '...', 'tool_name': 'search'}
Each call carries a unique nonce. The NonceTracker maintains a time-windowed set of used nonces (default: 5 minutes). Duplicate nonces are rejected.
from crewai_mcps import NonceTracker
tracker = NonceTracker(max_age_seconds=300)
nonce = tracker.generate()
# First use: OK
tracker.check_and_consume(nonce) # True
# Replay attempt: blocked
tracker.check_and_consume(nonce) # False
When tools are discovered from an MCP server, their definitions (name, description, schema) are hashed and pinned. If the server changes a tool's definition between calls, execution is blocked with a ToolIntegrityError.
from crewai_mcps import ToolPinner
pinner = ToolPinner()
pinner.pin("write_file", {
"name": "write_file",
"description": "Write a file to disk",
"schema": {"type": "object", "properties": {"path": {"type": "string"}}},
})
# Later: server changes the tool
pinner.verify("write_file", {
"name": "write_file",
"description": "Write a file to disk",
"schema": {
"type": "object",
"properties": {
"path": {"type": "string"},
"exec_cmd": {"type": "string"}, # Injected!
},
},
})
# => False
Every signed call, response, error, and security event is recorded with monotonically increasing sequence numbers. Export the full trail for compliance.
from crewai_mcps import AuditTrail
audit = AuditTrail(max_events=10000)
# Events are recorded automatically when used with SecureMCPTool
secure = SecureMCPTool(audit_trail=audit)
# Query the trail
audit.get_events_for_tool("search")
audit.get_security_alerts()
audit.get_errors()
# Export
audit.export_json("trail.json")
print(audit.summary())
Standalone verifier for matching responses to signed requests with timing checks.
from crewai_mcps import ResponseVerifier
verifier = ResponseVerifier(max_response_age=30.0)
verifier.register_request("nonce-1", "search", {"q": "test"}, envelope)
# Later...
result = verifier.verify_response("nonce-1", "search", response)
if result.valid:
print("Response verified")
else:
print(f"Verification failed: {result.errors}")
CrewAI Agent
|
v
SecureToolProxy (wraps each MCP tool)
|
+-- ToolPinner.verify() # Check definition integrity
+-- SecureMCPTool.sign() # Sign with nonce + timestamp
+-- original_tool.run() # Execute the real tool
+-- verify_response() # Log and verify result
+-- AuditTrail.log() # Record everything
| Class | Purpose |
|---|---|
| SecureMCPTool | Main entry point. Wraps tools, signs calls, verifies responses |
| SecureToolProxy | Transparent proxy that intercepts tool execution |
| KeyManager | Manages cryptographic key pairs |
| NonceTracker | Generates and validates nonces with TTL |
| ToolPinner | Hashes and pins tool definitions |
| ResponseVerifier | Matches responses to requests with timing checks |
| AuditTrail | Thread-safe structured event log |
| install_crewai_hooks | Registers MCPS as global CrewAI tool hooks |
cryptography >= 41.0crewai >= 0.80.0 (optional, for hook integration)Apache 2.0. See LICENSE.
Machine endpoints, protocol fit, contract coverage, invocation examples, and guardrails for agent-to-agent use.
Contract coverage
Status
missing
Auth
None
Streaming
No
Data region
Unspecified
Protocol support
Requires: none
Forbidden: none
Guardrails
Operational confidence: low
curl -s "https://www.xpersona.co/api/v1/agents/crewai-razashariff-crewai-mcps/snapshot"
curl -s "https://www.xpersona.co/api/v1/agents/crewai-razashariff-crewai-mcps/contract"
curl -s "https://www.xpersona.co/api/v1/agents/crewai-razashariff-crewai-mcps/trust"
Trust and runtime signals, benchmark suites, failure patterns, and practical risk constraints.
Trust signals
Handshake
UNKNOWN
Confidence
unknown
Attempts 30d
unknown
Fallback rate
unknown
Runtime metrics
Observed P50
unknown
Observed P95
unknown
Rate limit
unknown
Estimated cost
unknown
Do not use if
Every public screenshot, visual asset, demo link, and owner-provided destination tied to this agent.
Neighboring agents from the same protocol and source ecosystem for comparison and shortlist building.
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
The Frontend for Agents & Generative UI. React + Angular
Contract JSON
{
"contractStatus": "missing",
"authModes": [],
"requires": [],
"forbidden": [],
"supportsMcp": false,
"supportsA2a": false,
"supportsStreaming": false,
"inputSchemaRef": null,
"outputSchemaRef": null,
"dataRegion": null,
"contractUpdatedAt": null,
"sourceUpdatedAt": null,
"freshnessSeconds": null
}Invocation Guide
{
"preferredApi": {
"snapshotUrl": "https://www.xpersona.co/api/v1/agents/crewai-razashariff-crewai-mcps/snapshot",
"contractUrl": "https://www.xpersona.co/api/v1/agents/crewai-razashariff-crewai-mcps/contract",
"trustUrl": "https://www.xpersona.co/api/v1/agents/crewai-razashariff-crewai-mcps/trust"
},
"curlExamples": [
"curl -s \"https://www.xpersona.co/api/v1/agents/crewai-razashariff-crewai-mcps/snapshot\"",
"curl -s \"https://www.xpersona.co/api/v1/agents/crewai-razashariff-crewai-mcps/contract\"",
"curl -s \"https://www.xpersona.co/api/v1/agents/crewai-razashariff-crewai-mcps/trust\""
],
"jsonRequestTemplate": {
"query": "summarize this repo",
"constraints": {
"maxLatencyMs": 2000,
"protocolPreference": [
"OPENCLEW"
]
}
},
"jsonResponseTemplate": {
"ok": true,
"result": {
"summary": "...",
"confidence": 0.9
},
"meta": {
"source": "GITHUB_REPOS",
"generatedAt": "2026-10-10T01:53:03.380Z"
}
},
"retryPolicy": {
"maxAttempts": 3,
"backoffMs": [
500,
1500,
3500
],
"retryableConditions": [
"HTTP_429",
"HTTP_503",
"NETWORK_TIMEOUT"
]
}
}Trust JSON
{
"status": "unavailable",
"handshakeStatus": "UNKNOWN",
"verificationFreshnessHours": null,
"reputationScore": null,
"p95LatencyMs": null,
"successRate30d": null,
"fallbackRate": null,
"attempts30d": null,
"trustUpdatedAt": null,
"trustConfidence": "unknown",
"sourceUpdatedAt": null,
"freshnessSeconds": null
}Capability Matrix
{
"rows": [
{
"key": "OPENCLEW",
"type": "protocol",
"support": "unknown",
"confidenceSource": "profile",
"notes": "Listed on profile"
},
{
"key": "crewai",
"type": "capability",
"support": "supported",
"confidenceSource": "profile",
"notes": "Declared in agent profile metadata"
},
{
"key": "multi-agent",
"type": "capability",
"support": "supported",
"confidenceSource": "profile",
"notes": "Declared in agent profile metadata"
}
],
"flattenedTokens": "protocol:OPENCLEW|unknown|profile capability:crewai|supported|profile capability:multi-agent|supported|profile"
}Facts JSON
[
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Razashariff",
"href": "https://github.com/razashariff/crewai-mcps",
"sourceUrl": "https://github.com/razashariff/crewai-mcps",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T22:22:10.371Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/crewai-razashariff-crewai-mcps/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/crewai-razashariff-crewai-mcps/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-09T22:22:10.371Z",
"isPublic": true
},
{
"factKey": "docs_crawl",
"category": "integration",
"label": "Crawlable docs",
"value": "6 indexed pages on the official domain",
"href": "https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar",
"sourceUrl": "https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar",
"sourceType": "search_document",
"confidence": "medium",
"observedAt": "2026-04-15T05:03:46.393Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/crewai-razashariff-crewai-mcps/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/crewai-razashariff-crewai-mcps/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
]Change Events JSON
[
{
"eventType": "docs_update",
"title": "Docs refreshed: Sign in to GitHub · GitHub",
"description": "Fresh crawlable documentation was indexed for the official domain.",
"href": "https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar",
"sourceUrl": "https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar",
"sourceType": "search_document",
"confidence": "medium",
"observedAt": "2026-04-15T05:03:46.393Z",
"isPublic": true
}
]Sponsored
Ads related to crewai-mcps and adjacent AI workflows.