Security audit
PLUR Memory Engine
Security checks across malware telemetry and agentic risk
Overview
This memory plugin is purpose-aligned, but it automatically changes OpenClaw configuration and adds persistent agent-memory behavior with too little explicit user control.
Review this carefully before installing. It is not clearly malicious, but installation can automatically enable persistent memory, grant conversation access, alter SYSTEM.md, and configure an MCP server. Install only if you want cross-session memory and are comfortable auditing ~/.openclaw/openclaw.json and ~/.plur afterward.
SkillSpector
By NVIDIA
SkillSpector was not run because this plugin release contains no bundled skills.
VirusTotal
61/61 vendors flagged this plugin as clean.
Static analysis
No suspicious patterns detected.
