Back to plugin

Security audit

Thunder Openclaw Plugin

Security checks across malware telemetry and agentic risk

Overview

This appears to be a real Thunder Compute integration, but it needs Review because it lets an agent control paid GPU resources, run remote commands, delete instances, and store OAuth tokens locally.

Install this only if you want OpenClaw to manage your Thunder Compute account. Before using it, verify the endpoint, authenticate only on a trusted machine, require the agent to confirm instance type, price, command, and deletion targets, monitor billing, and clear/revoke OAuth access when finished.

VirusTotal

No VirusTotal findings

View on VirusTotal

Static analysis

No suspicious patterns detected.