Environment variable access combined with network send.
- Code
- suspicious.env_credential_access
- Location
- dist/src/server.js:247
- Evidence
env: { ...process.env, HOME: homedir() },
Security audit
Security checks for vulnerabilities and agentic risk
This is a disclosed Cognee memory plugin that stores and recalls agent memory; its sensitive behavior is substantial but aligned with that purpose.
Install only if you want Cognee to become a long-term memory backend for OpenClaw. It can store prompts, answers, tool-call traces, and selected memory files in Cognee, inject recalled memory into future prompts, run local background helper processes, and delete indexed memory when explicitly requested through its tools or CLI. Review the dataset, cloud/API-key, autoIndex, captureSession, and hook-permission settings before enabling it.
SkillSpector was not run because this plugin release contains no bundled skills.
Detected: suspicious.env_credential_access
env: { ...process.env, HOME: homedir() },