Back to skill

Security audit

Semantic Memory Search

Security checks across malware telemetry and agentic risk

Overview

This skill is for local memory search, but it also documents daily Discord reporting for sensitive memory indexing without clearly explaining or limiting what leaves the machine.

Review this before installing. Use it only if you are comfortable indexing your OpenClaw memory files, and disable or remove any Discord notification path unless you explicitly want external reporting and know exactly what data is sent. Restrict indexed paths to files you approve.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill states that daily indexing results are pushed to Discord, but provides no warning about data egress, content sensitivity, or what information may be included in those notifications. Because the indexed sources include memory files such as MEMORY.md, USER.md, TOOLS.md, and AGENTS.md, this creates a realistic risk of leaking sensitive metadata, filenames, summaries, or operational details to a third-party service.

VirusTotal

No VirusTotal findings

View on VirusTotal

Static analysis

No suspicious patterns detected.