Higgsfield MCP
Security checks across static analysis, malware telemetry, and agentic risk
Overview
The bundle appears to do exactly what it says — it configures an OpenClaw connector to Higgsfield's remote MCP endpoint — and its files and instructions are proportionate to that purpose.
This bundle is coherent for connecting OpenClaw to Higgsfield. The main residual risk is that it runs 'npx mcp-remote@0.1.38' which will download and execute code from the npm registry at runtime — this is expected for an stdio bridge but means you should trust the mcp-remote package and Higgsfield. If you want extra caution: (1) review the mcp-remote package source (or vendor a vetted binary) before using, (2) run the connector in a restricted environment if possible, and (3) be mindful that image/video generations will consume your Higgsfield credits and never paste account/session tokens into prompts or logs.
SkillSpector
SkillSpector findings are pending for this release.
Static analysis
No static analysis findings were reported for this release.
VirusTotal
No VirusTotal findings
