
Security News
Open VSX Unblocks Extension IDs Used in Malware Campaign
Open VSX has removed three extension IDs from its malicious-extension list as the legitimate publishers they impersonated move to claim the names for themselves.
@aauth/mcp-openclaw
Advanced tools
OpenClaw plugin for connecting to AAuth-authenticated MCP servers. Discovers remote tools via MCP and registers them as OpenClaw tools with AAuth signing.
Part of aauth-dev/packages-js. Protocol spec: dickhardt/AAuth.
npm install @aauth/mcp-openclaw
Add to ~/.openclaw/openclaw.json:
{
"plugins": {
"entries": {
"aauth": {
"enabled": true,
"config": {
"agent_url": "https://user.github.io",
"delegate": "openclaw",
"mcp_servers": {
"my-files": "https://files-api.example.com/mcp",
"my-db": "https://db-api.example.com/mcp"
}
}
}
}
}
}
Tools from remote servers are registered with a prefix: my-files_read_file, my-db_query, etc.
register(api, config)Plugin entry point called by OpenClaw. Connects to configured MCP servers and registers their tools.
import { register } from '@aauth/mcp-openclaw'
ServerManagerManages connections to multiple MCP servers with AAuth authentication.
import { ServerManager } from '@aauth/mcp-openclaw'
const manager = new ServerManager({
servers: {
'my-files': 'https://files-api.example.com/mcp',
'my-db': 'https://db-api.example.com/mcp',
},
getKeyMaterial: async () => ({
signingKey: privateKeyJwk,
signatureKey: { type: 'jwt', jwt: agentToken }
}),
})
await manager.connectAll()
// List discovered tools (prefixed by server name)
const tools = manager.getTools()
// [{ prefixedName: 'my-files_read', serverName: 'my-files', originalName: 'read', description: '...' }]
// Call a tool
const result = await manager.callTool('my-files_read', { path: '/data.json' })
await manager.shutdown()
MIT
FAQs
OpenClaw plugin for AAuth-authenticated MCP server connections
We found that @aauth/mcp-openclaw demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.

Security News
Open VSX has removed three extension IDs from its malicious-extension list as the legitimate publishers they impersonated move to claim the names for themselves.

Product
Socket’s PHP and Composer support is now in Beta for all customers, with PHP reachability analysis generally available.

Product
Socket is bringing experimental protection to Firefox, scanning 97,000+ extensions in Mozilla's official directory for malware and risky updates.