OnionClaw for Openclaw

OnionClaw is an advanced Tor-based OSINT framework for searching dark web engines, scraping hidden services, and generating AI-powered threat intelligence reports.

jacobjandon
v2.1.13
Mar 17, 2026
0
1.1k
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install onionclaw

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install onionclaw using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is OnionClaw?

OnionClaw serves as a specialized toolkit for navigating the complexities of the Tor network and the dark web. It routes all traffic through Tor, allowing developers and security researchers to query 12 verified dark web search engines simultaneously, fetch content from .onion hidden services, and rotate identities to ensure anonymity. As a key component for Openclaw Skills, it bridges the gap between raw dark web data and actionable insights.

The tool is designed for high-stakes investigations, providing the ability to monitor for leaked credentials, track ransomware groups, and perform general threat intelligence. By integrating with LLMs, OnionClaw can synthesize raw page data into structured reports, making it an essential asset for any sophisticated cybersecurity or OSINT workflow.

OnionClaw Use Cases

  • Investigating ransomware group activities and their dedicated leak sites.
  • Searching for corporate data breaches or leaked credentials across multiple dark web indexes.
  • Monitoring for personal identity exposure and PII leaks on hidden services.
  • Scraping and analyzing .onion pages for security research without exposing a clearnet IP.
  • Generating automated threat intelligence feeds in STIX or MISP formats for security operations centers.

How OnionClaw Works

  1. Connectivity Check: The system verifies the Tor connection and exit IP to ensure anonymity before starting any operation.
  2. Multi-Engine Search: Queries are sent to 12 dark web engines like Ahmia and OnionLand to gather a broad set of deduplicated results.
  3. Content Retrieval: The tool fetches the full text of .onion URLs, handling the specific proxying requirements of the Tor network.
  4. AI-Driven Analysis: Raw data is processed through an LLM using specific modes like threat_intel or ransomware to extract relevant artifacts.
  5. Structured Export: The investigation results are compiled into professional reports or machine-readable formats for further automation.

OnionClaw Setup

To get started with OnionClaw as part of your Openclaw Skills library, follow these steps:

# Install required Python dependencies
pip3 install requests[socks] beautifulsoup4 python-dotenv stem

# Run the interactive setup wizard to configure .env and torrc
python3 setup.py

# Ensure the Tor service is running on your machine
# For macOS:
brew services start tor
# For Linux:
sudo systemctl start tor

OnionClaw Data Schema & Taxonomy

OnionClaw organizes data through a multi-layered schema designed for both human readability and machine interoperability:

Data Component Description
Search Results JSON objects containing title, URL, and the source engine name.
Scraped Data Markdown-formatted text including page titles, links, and HTTP status codes.
OSINT Reports Structured Markdown or JSON sectioned by mode (e.g., threat indicators, victims).
Threat Intelligence STIX 2.1 bundles and MISP-compliant events for ingestion into security platforms.
Cache Local storage of search queries and page content to speed up repetitive tasks.

OnionClaw Advanced Features

  • Circuit Rotation: Programmatically renew Tor identities and circuits via the ControlPort to bypass rate limits and enhance privacy.
  • Automated Robin Pipeline: A single-command workflow that handles query refinement, searching, scraping, and reporting automatically.
  • Persistent Watch Jobs: Schedule recurring dark web monitoring tasks with customizable polling intervals and alerting.
  • Flexible Inference: Support for both cloud-based LLMs and local providers like Ollama for completely air-gapped or private analysis.
  • Resumable Jobs: Checkpoint system that allows large-scale scrape and analysis jobs to be resumed if interrupted.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*