Back to plugin

Security audit

ReMe

Security checks for vulnerabilities and agentic risk

Overview

ReMe is a disclosed long-term memory plugin that captures and recalls conversation history through a configured ReMe service, with no evidence of hidden exfiltration or destructive behavior.

Install only if you want OpenClaw conversations to be captured into long-term memory. Keep the ReMe service bound to loopback or an authenticated proxy, review the chosen ReMe workspace because it will hold durable conversation-derived memory, and disable automatic capture/recall/consolidation if those defaults are too broad for your use case.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
openclaw.plugin.json:16
Evidence
"placeholder": "http://127.0.0.1:2333"