Back to skill

Security audit

Memoria

Security checks across malware telemetry and agentic risk

Overview

Memoria is a disclosed long-term memory skill whose sensitive behavior is expected for its purpose, but users should be careful about what they store and how they handle API keys.

Install this only if you want OpenClaw to retain and reuse information across sessions. Avoid storing secrets unless necessary, periodically review or delete saved memories, keep API keys out of shared logs or screenshots, and inspect or trust the remote installer/source before running optional local setup commands.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger phrases include common conversational requests such as 'remember this', 'save to memory', and 'what do you remember', which are broad enough to match ordinary dialogue unexpectedly. In a skill that performs durable memory operations, unintended invocation can cause accidental storage, retrieval, modification, or deletion of long-term memory, increasing privacy and integrity risk.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill explicitly instructs storing durable user preferences, profile facts, and even secrets if the user asks, but it does not require a user-facing privacy warning, retention notice, or confirmation flow before persistence. In a long-term memory skill, this increases the risk of over-collection, unintended retention, and later disclosure of sensitive data across sessions, especially because the guidance normalizes durable storage as a default workflow.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The setup instructions ask users to provide sensitive API keys and perform remote/plugin installation, but they do not warn about protecting credentials, validating endpoints, or the trust implications of installing third-party code. In a memory plugin context, these credentials may grant access to long-term stored conversation data, increasing the sensitivity of mishandling or disclosure.

VirusTotal

46/46 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.