Mengram Openclaw Skill
Security checks across static analysis, malware telemetry, and agentic risk
Overview
The skill's code, scripts, and runtime instructions are consistent with a long-term memory integration that sends user messages to the Mengram API using a single API key; it behaves as advertised but has a few small implementation/privacy issues you should consider before installing.
This skill is internally consistent for providing remote long-term memory: it will send conversation text, workflows, and failure contexts to https://mengram.io using the MENGRAM_API_KEY you provide. Before installing, verify you trust the Mengram service and its privacy policy, avoid storing highly sensitive data (passwords, credit card numbers, medical details) in memories, and consider using a limited-scope API key if the service supports it. Note two small issues to review: the scripts accept an override MENGRAM_BASE_URL (not declared in metadata), and the setup check prints the first 10 characters of your API key to stdout (contradicting README claims). If you want stronger assurances, inspect the upstream GitHub repo, confirm where the mengram.io backend is hosted, and test the skill in a sandboxed environment before granting it access to production conversations.
SkillSpector
SkillSpector findings are pending for this release.
Static analysis
Static analysis findings are pending for this release.
VirusTotal
VirusTotal findings are pending for this skill version.
