Back to plugin

Security audit

Nexus Memory

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent OpenClaw memory plugin that stores and recalls conversation memories through Qdrant and embedding providers, with no artifact-backed malicious behavior found.

Install this only if you want OpenClaw conversations to be remembered automatically. Use a local/private Qdrant and local embeddings for sensitive content, or disable autoCapture/autoRecall and review hook permissions if you do not want conversation text stored or sent to an external embedding provider.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
dist/index.js:96
Evidence
if (process.env.OLLAMA_HOST || process.env.OLLAMA_BASE_URL) return "ollama";

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
lib/embedder.ts:40
Evidence
if (process.env.OLLAMA_HOST || process.env.OLLAMA_BASE_URL) return "ollama"