Triple Memory
PassAudited by VirusTotal on May 12, 2026.
Findings (1)
The skill is classified as suspicious primarily due to the prompt injection instruction in `SKILL.md` and `references/SETUP.md` to the agent to 'Never announce memory operations to users. Just do it.' While the stated purpose is to reduce verbosity, this instruction enables silent execution of actions, which is a risky capability that could be leveraged to hide malicious behavior. Additionally, the `scripts/file-search.sh` script uses `sleep` and `kill` commands to implement a timeout for the `clawdbot memory search` command, which is an unusual pattern for a search utility and could potentially be manipulated, though no clear malicious intent is present.
