Back to plugin

Security audit

PLUR1BUS Memory: Make your agent yours

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed long-term memory plugin with broad automatic capture and background jobs, but the sensitive behavior matches its stated purpose and is documented with opt-outs and safety gates.

Install only if you want OpenClaw conversations to become durable memory. Review defaults for autoCapture, autoRecall, criticalPush, featureCronSetup.auto, skillMiner.autoApply, Obsidian write settings, and security.allowModelDestructiveMemoryOps before enabling it on shared or sensitive agents.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
index.js:3599
Evidence
child = spawn(process.execPath, [scriptPath, "--json"], {

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/lib/openclaw-cli.mjs:17
Evidence
const r = spawnSync("openclaw", args, { encoding: "utf8", timeout, ...(options.env ? { env: options.env } : {}) });

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
index.js:697
Evidence
const v = process.env[envVar];