Fluent

Security checks across malware telemetry and agentic risk

Overview

The package appears to do what it claims: an OpenClaw Fluent client plugin that manages hosted auth, MCP binding, and bundles several Fluent skills; its requirements, instructions, and included code are proportionate to that purpose.

This package is internally coherent for providing Fluent integration in OpenClaw: it will manage hosted OAuth tokens and rewrite the mcp.servers.fluent entry in your OpenClaw config when you run the provided CLI commands. If you plan to install it: (1) review hosted-auth.js or the login flow if you want to understand how OAuth callbacks are handled (it likely opens a browser and stores a token), (2) back up your OpenClaw config before letting the plugin rewrite mcp.servers.fluent, and (3) verify you trust the package source (shaner-git). Although I found no incoherent or disproportionate requests, you should still inspect the hosted-auth and plugin-actions code if you require higher assurance about token storage and callback handling.

SkillSpector

By NVIDIA

SkillSpector findings are pending for this release.

VirusTotal

No VirusTotal findings

View on VirusTotal