Security audit
Graphify MCP
Security checks for vulnerabilities and agentic risk
Overview
This package is a disclosed Graphify MCP connector for querying indexed repositories via OAuth, with no bundled runtime code or hidden installer behavior found.
Install this only if you intend to connect OpenClaw to your Graphify account and allow the agent to query repositories already indexed in Graphify. Review Graphify's OAuth prompt and tool approvals, and be careful with memory tools because they may persist or modify repository knowledge.
SkillSpector was not run because this plugin release contains no bundled skills.
Static analysis
No suspicious patterns detected.
