Back to skill

Security audit

Memory Crystal Private

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed local memory system that captures and indexes AI conversations, with sensitive access that is expected for its purpose.

Install only if you want a persistent memory layer that captures AI conversations by default. Review the cron job, Claude/OpenClaw hooks, private-mode controls, embedding provider/API key setup, and any hosted relay configuration before enabling it.

SkillSpector

By NVIDIA

SkillSpector could not complete.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access, suspicious.potential_exfiltration (+1 more)

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
_trash/finder-duplicates-2026-04-16/src/crystal-serve 2.ts:108

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
_trash/finder-duplicates-2026-04-16/src/doctor 2.ts:211

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
_trash/finder-duplicates-2026-04-16/src/installer 2.ts:129

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
_trash/finder-duplicates-2026-04-16/src/llm 2.ts:69

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/bridge.ts:20

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/cli.ts:218

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/core.ts:300

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/crystal-serve.ts:108

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/dev-update.ts:51

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/doctor.ts:91

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/installer.ts:100

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/ldm.ts:239

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/llm.ts:100

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/mlx-setup.ts:57

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/staging.ts:148

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
_trash/finder-duplicates-2026-04-16/src/file-sync 2.ts:17

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
_trash/finder-duplicates-2026-04-16/src/llm 2.ts:121

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
src/cc-hook.ts:33

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
src/core.ts:1540

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
src/file-sync.ts:17

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
src/llm.ts:62

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
src/mirror-sync.ts:21

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
src/poller.ts:28

Sensitive-looking file read is paired with a network send.

Warn
Code
suspicious.potential_exfiltration
Location
_trash/finder-duplicates-2026-04-16/src/llm 2.ts:68

Sensitive-looking file read is paired with a network send.

Warn
Code
suspicious.potential_exfiltration
Location
src/core.ts:1625

Sensitive-looking file read is paired with a network send.

Warn
Code
suspicious.potential_exfiltration
Location
src/llm.ts:99

Prompt-injection style instruction pattern detected.

Warn
Code
suspicious.prompt_injection_instructions
Location
ai/product/plans-prds/current/2026-03-15--cc-mini--search-quality-qmd-v2-port.md:60