Back to plugin

Security audit

YantrikDB Memory for OpenClaw

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed YantrikDB-backed memory plugin that stores and recalls conversation memory through a configured HTTP endpoint, with no hidden install or local-system behavior found.

Install only if you want a persistent memory backend and trust the configured YantrikDB server. Keep the default local URL or use HTTPS/trusted networking for remote servers, review whether autoCapture should remain enabled, and avoid granting conversation access unless automatic memory capture is desired.

SkillSpector

By NVIDIA

SkillSpector was not run because this plugin release contains no bundled skills.

VirusTotal

61/61 vendors flagged this plugin as clean.

View on VirusTotal

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
openclaw.plugin.json:20
Evidence
"description": "YantrikDB HTTP gateway URL. Defaults to http://127.0.0.1:7438 (or YANTRIKDB_URL)."