Back to skill
v1.2.0

ClawBrain Memory

ReviewClawScan verdict for this skill. Analyzed May 1, 2026, 8:35 AM.

Analysis

This skill is clearly a long-term memory tool, but it asks to automatically retain and manage conversation memories without clear limits, retention rules, or data-boundary details.

GuidanceTreat this as a Review item before installing. The memory purpose is disclosed and coherent, but it is broad: it claims to remember conversation content, user identity changes, original quotes, and summaries across sessions, with automatic daily maintenance and an external dashboard. Do not use it with sensitive personal, business, legal, financial, or credential-related conversations unless you can confirm exactly what is stored, where it is stored, how long it is retained, who can access it, and how to delete or disable it.

Findings (3)

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

Abnormal behavior control

Checks for instructions or behavior that redirect the agent, misuse tools, execute unexpected code, cascade across systems, exploit user trust, or continue outside the intended task.

Rogue Agents
SeverityMediumConfidenceHighStatusConcern
SKILL.md
安装后自动生效... 每日自动整理记忆:合并重复内容、提炼摘要、清理过时信息,无需手动维护。

The skill describes automatic activation and recurring memory maintenance without stating user approval, scheduling, opt-out, or rollback controls.

User impactThe agent may continue changing persistent memory state after installation without explicit per-action confirmation.
RecommendationUse only if you can review, pause, export, and delete memory changes, and avoid installing it where automatic persistent state changes are not acceptable.
Sensitive data protection

Checks for exposed credentials, poisoned memory or context, unclear communication boundaries, or sensitive data that could leave the user's control.

Memory and Context Poisoning
SeverityHighConfidenceHighStatusConcern
SKILL.md
自动记住对话内容、区分原话与摘要、长对话不丢失、身份实时更新。让龙虾真正记住一切。

The skill explicitly aims to automatically retain conversation content, original wording, summaries, and identity information long-term.

User impactSensitive personal or work information shared in chats could be stored and reused in future sessions, and incorrect or outdated memories could influence later answers.
RecommendationInstall only if you are comfortable with broad long-term memory. Before using it, look for clear controls for what is saved, how to delete memories, retention limits, and whether sensitive chats can be excluded.
Insecure Inter-Agent Communication
SeverityMediumConfidenceMediumStatusConcern
SKILL.md
当记忆服务暂时不可用时... 在 [clawbrain.dev/dashboard](https://clawbrain.dev/dashboard) 的记忆库页面:- 记忆浏览和管理

The artifact indicates a memory service and external dashboard for managing stored memories, but does not define data boundaries, authentication, access controls, or retention behavior.

User impactConversation memories may be handled by an external service, and the artifacts do not make clear what is uploaded, who can access it, or how it is secured.
RecommendationVerify the service provider, privacy policy, authentication model, and memory storage/deletion controls before connecting sensitive conversations.