Flow Weaver

Security checks across static analysis, malware telemetry, and agentic risk

Overview

The skill's code, instructions, and requirements are consistent with its stated purpose (exposing Flow Weaver workflow tools inside OpenClaw); nothing obvious or disproportionate is requested or installed.

This plugin appears coherent and implements what it promises (workflow authoring, compile/run, deploy integration). Before installing: 1) Review the peer dependency @synergenius/flow-weaver (it will perform network calls and manage deployments/login flows). 2) Expect local credential storage at ~/.fw/credentials.json if you use fw login; audit that flow before using deploy/marketplace commands. 3) Be aware the plugin exposes HTTP routes and a scheduler—if you don't need the Studio bridge or webhooks, disable those features. 4) Because the plugin executes compiled workflows from your workspace, review any workflow code you run (compiled workflows may invoke further actions). If you want to be extra cautious, install in a dedicated workspace, inspect package.json/dependencies, and test in dry-run mode first.

Static analysis

No static analysis findings were reported for this release.

VirusTotal

No VirusTotal findings

View on VirusTotal

Risk analysis

No visible risk-analysis findings were reported for this release.