Flow Weaver
Security checks across static analysis, malware telemetry, and agentic risk
Overview
The skill's code, instructions, and requirements are consistent with its stated purpose (exposing Flow Weaver workflow tools inside OpenClaw); nothing obvious or disproportionate is requested or installed.
This plugin appears coherent and implements what it promises (workflow authoring, compile/run, deploy integration). Before installing: 1) Review the peer dependency @synergenius/flow-weaver (it will perform network calls and manage deployments/login flows). 2) Expect local credential storage at ~/.fw/credentials.json if you use fw login; audit that flow before using deploy/marketplace commands. 3) Be aware the plugin exposes HTTP routes and a scheduler—if you don't need the Studio bridge or webhooks, disable those features. 4) Because the plugin executes compiled workflows from your workspace, review any workflow code you run (compiled workflows may invoke further actions). If you want to be extra cautious, install in a dedicated workspace, inspect package.json/dependencies, and test in dry-run mode first.
Static analysis
No static analysis findings were reported for this release.
VirusTotal
No VirusTotal findings
Risk analysis
No visible risk-analysis findings were reported for this release.
