Back to skill

Security audit

ClawMem

Security checks across malware telemetry and agentic risk

Overview

This is a coherent setup skill for installing and verifying ClawMem, with disclosed configuration changes and credential use that users should handle carefully.

Install this only if you intend to make ClawMem the active memory plugin. Review the commands before running them, protect the OpenClaw config and ClawMem token, avoid sharing logs or screenshots that may expose credentials, and consider pinning or verifying the external plugin package source if your environment supports it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
86% confidence
Finding
This skill instructs the operator to extract a per-agent token from local configuration, export it into environment variables, and use it in `gh` or `curl` requests, but it does not include any warning about credential sensitivity, shell history, process exposure, logging, or avoiding disclosure in shared terminals. While the workflow appears operational rather than malicious, embedding token-handling and network request steps without guardrails increases the chance of accidental credential leakage or unsafe reuse in troubleshooting contexts.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.