0G ClawBack
PassAudited by VirusTotal on May 16, 2026.
Findings (1)
The bundle implements a 'stateless resumption' system that uploads the agent's workspace and memory to the 0G decentralized storage network. It is classified as suspicious due to the inclusion of a hardcoded Ethereum private key in the `.env` file and the inherent risk of automated data exfiltration of the entire workspace state. While the scripts (e.g., `scripts/clawback-secret-upload.js`) include encryption, the `SKILL.md` instructions require the agent to store the resulting encryption keys in a local `MEMORY.md` file, creating a significant security risk if that file is accessed by other entities.
