Is johnfire/openclaw-notesnook-mcp safe?
Yes. johnfire/openclaw-notesnook-mcp is safe to install. Oathe's behavioral security audit gave the openclaw-notesnook-mcp skill by johnfire a trust score of 90/100 with 3 findings, none critical or high.
https://github.com/johnfire/openclaw-notesnook-mcp
Is johnfire/openclaw-notesnook-mcp safe to install?
This MCP server provides legitimate note synchronization functionality between Notesnook and OpenClaw with no significant security risks detected. While system processes accessed honeypot files during authentication, the skill itself showed no malicious behavior and all canary files remained intact.
What security issues were found in johnfire/openclaw-notesnook-mcp?
Category Scores
Findings (3)
MEDIUM System Process Honeypot Access -15 ▶
Monitoring detected access to honeypot files (.env, SSH keys, AWS credentials), but investigation shows these were from legitimate system processes (sshd, sudo) during authentication, not from the skill itself.
LOW Node.js Runtime Dependency -20 ▶
Skill requires Node.js runtime and npm dependencies, which inherently carry standard execution risks associated with JavaScript applications.
INFO Filesystem Sync Model -10 ▶
Uses filesystem-based sync between Notesnook and OpenClaw, which requires file system access permissions but appears to be properly scoped.
Should I install johnfire/openclaw-notesnook-mcp?
Oathe's verdict for johnfire/openclaw-notesnook-mcp is SAFE with a trust score of 90/100. Recommendation: Install.