Back to plugin

Security audit

OpenLTM Memory

Security checks for vulnerabilities and agentic risk

Overview

This plugin provides disclosed local long-term memory tools for OpenClaw and its sensitive behavior is aligned with that purpose.

Install only if you want agents to keep and reuse local long-term memories across sessions and compatible tools. Review stored memories periodically, avoid saving secrets or sensitive personal data, and disable autoRecall if you do not want prior memories automatically added to prompts.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/index.ts:39
Evidence
const out = execSync(cmd, { encoding: "utf-8", stdio: "pipe" }).trim();