Back to plugin

Security audit

XMemo for OpenClaw

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed XMemo cloud memory plugin that can read, write, delete, and cache user memory data, but those capabilities match its stated purpose.

Install only if you want OpenClaw to use XMemo as an active long-term memory backend. Review the configured XMemo account, API-key scopes, readBucket setting, and autoCapture setting before use, because visible XMemo memories may be searched and new memories may be stored or deleted through the plugin tools.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

No suspicious patterns detected.