No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by agentscope-ai · MCP Server · ★ 35.2k
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is QwenPaw safe to install? View the security audit →
QwenPaw [
Open-source 24/7 Cowork app for OpenClaw, Hermes, Claude Code, Codex, OpenCode and 20+ more CLI Agent | Custom
Build Agentic workflows, RAG pipelines, with rich AI model and tool support on one collaborative workspace. De
Explore other popular mcp server tools:
QwenPaw is Your Personal AI Assistant; easy to install, deploy on your own machine or on the cloud; supports multiple chat apps with easily extensible capabilities.. It is categorized as a MCP Server with 35.2k GitHub stars.
QwenPaw is primarily written in TypeScript. It covers topics such as agent, agent-harness, agentscope.
You can find installation instructions and usage details in the QwenPaw GitHub repository at github.com/agentscope-ai/QwenPaw. The project has 35.2k stars and 3120 forks, indicating an active community.
QwenPaw is released under the Apache-2.0 license, making it free to use and modify according to the license terms.
The top alternatives to QwenPaw on Agent Skills Hub include nanobot, lobehub, holaOS. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: