Security audit
Hivemind
Security checks for vulnerabilities and agentic risk
Overview
The package mainly matches its shared-memory purpose, but it also runs background agents and can automatically write global Claude skills from past conversations, which needs careful review before installing.
Install only if you are comfortable with conversation history and source-derived code graph metadata being stored in Deeplake and shared within the selected org/workspace. Pay special attention to the automatic skill mining path: it can run background agent CLIs and write generated SKILL.md files under ~/.claude/skills, affecting future agent behavior outside OpenClaw.
SkillSpector was not run because this plugin release contains no bundled skills.
Static analysis
No suspicious patterns detected.
