Higgsfield MCP

Security checks across static analysis, malware telemetry, and agentic risk

Overview

The bundle appears to do exactly what it says — it configures an OpenClaw connector to Higgsfield's remote MCP endpoint — and its files and instructions are proportionate to that purpose.

This bundle is coherent for connecting OpenClaw to Higgsfield. The main residual risk is that it runs 'npx mcp-remote@0.1.38' which will download and execute code from the npm registry at runtime — this is expected for an stdio bridge but means you should trust the mcp-remote package and Higgsfield. If you want extra caution: (1) review the mcp-remote package source (or vendor a vetted binary) before using, (2) run the connector in a restricted environment if possible, and (3) be mindful that image/video generations will consume your Higgsfield credits and never paste account/session tokens into prompts or logs.

SkillSpector

By NVIDIA

SkillSpector findings are pending for this release.

Static analysis

No static analysis findings were reported for this release.

VirusTotal

No VirusTotal findings

View on VirusTotal