๐Ÿฉบ memory-health-check

Security checks across malware telemetry and agentic risk

Overview

This is a coherent local memory health-check skill, but its optional repair commands can delete local memory files, so users should preview and back up before using repair.

Install only if you are comfortable with this skill inspecting local OpenClaw memory. Run diagnostics first, use --dry-run before repair, back up memory before deleting orphans, and do not grant purchase or crypto authority for this skill unless a separate reviewed flow justifies it. VirusTotal was pending, while static and manual artifact review did not show malicious behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The README advertises auto-repair and orphan removal commands that can delete or modify memory files, but it does not prominently warn users about destructive behavior or define what qualifies as an orphan. In an agent skill context, unclear documentation around deletion is dangerous because users or higher-level automation may invoke these commands assuming they are diagnostic-only, leading to unintended data loss.

VirusTotal

60/60 vendors flagged this skill as clean.

View on VirusTotal