A lightweight and safe Python Agent framework with tool execution, middleware-based authorization, and MCP tool projection support
CloseClaw has 15 tools with complete input schemas and descriptions, but quality is inconsistent. Naming follows verb_noun convention (call_cron, read_pdf, write_file, shell). Descriptions range from adequate (read_pdf: 156 chars) to minimal (pwd: 28 chars). Most parameters have type and description, but several lack actionable constraints. No output schemas documented. Error handling is absent, tools do not guide recovery or categorize failures. Security concerns: shell tool is unrestricted; no permission gates; no audit trail declarations. Composition is reasonable (single responsibility per tool), but critical tools like shell lack dry-run or confirmation patterns.
Schedule a one-time wake-up at a fixed time (no auth required, requires explicit target channel)
Edit a file by replacing old_text with new_text
Edit a memory file by replacing old_text with new_text under CloseClaw Memory
Fetch content from a URL via HTTP GET
Print current working directory
Read contents of a file, optionally by line range
Read an image from the local filesystem and embed it natively into your visual context. Use this to visually inspect screenshots, diagrams, photos, or plots.
shell tool lacks confirmation/dry-run pattern for destructive operations. Agents can execute arbitrary commands without safeguards, risking data loss or system compromise.
No output schemas documented for any tool. LLMs cannot predict response structure, forcing them to parse unstructured output and plan downstream calls blindly.
pwd description is 28 characters ('Print current working directory'), below 20-char threshold. Provides no context for when LLM should call it or what it returns.
No error handling guidance. Tools do not categorize failures as retryable, user-fixable, or fatal. LLMs receive raw errors with no recovery path.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | D | 59 | 2026-07-28+ | v2 |
Extract text from a PDF file. Use this for reading PDF documents, papers, manuals, or slides. Returns the file's text formatted as Markdown. Use start_page and max_pages to paginate through large documents.
Execute a shell command (Windows CMD or Unix shell)
Create a background subagent task for parallel research or execution
Cancel a running background task by task_id
Check status/result for a background task by task_id
Search the web for information (stub - configure search API for production)
Write content to a file (overwrites if exists)
Save memory/notes to a file (for automatic memory flush). Auto-approved system tool.
shell tool description does not warn about security risks or mention input sanitization. No permission gates or audit trail declarations present.