Back to plugin

Security audit

mnemostack Auto Recall

Security checks for vulnerabilities and agentic risk

Overview

This plugin coherently adds user-triggered local memory recall to OpenClaw prompts, with bounded defaults and disclosed backend behavior.

Install only if you intend OpenClaw to send recall-triggering user prompts and session metadata to your configured mnemostack backend. Keep the default loopback backend or another trusted endpoint, avoid exposing plugin configuration to untrusted users, and configure script backends only for commands you trust.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/backends/script.js:103
Evidence
const child = spawn(this.config.command, args, {