OpenClaw Memory Canonical
Security checks across static analysis, malware telemetry, and agentic risk
Overview
The package is internally consistent with its stated purpose: a local, file-based memory system that operates only on workspace files using included shell scripts and requires no credentials or network access.
This skill appears to do what it claims: local file-based memory management with included shell scripts. Before installing or re-syncing into memory/scripts/: (1) review the provided scripts (health-check.sh, atomic-write.sh, archive scripts) to confirm you accept their file operations; (2) back up your current memory/scripts/ and workspace memory/ and .learnings directories because the archive scripts move files and the runtime contract deletes lock files unconditionally; (3) run the health-check from a safe/test copy of your workspace first to observe behavior; and (4) note that no network or credential access is required, so risk is limited to on-disk modifications in the workspace.
SkillSpector
SkillSpector findings are pending for this release.
Static analysis
No static analysis findings were reported for this release.
VirusTotal
VirusTotal findings are pending for this skill version.
