Environment variable access combined with network send.
Critical
- Code
- suspicious.env_credential_access
- Location
- dist/index.js:96
- Evidence
if (process.env.OLLAMA_HOST || process.env.OLLAMA_BASE_URL) return "ollama";
Security audit
Security checks for vulnerabilities and agentic risk
This is a coherent OpenClaw memory plugin that stores and recalls conversation memories through Qdrant and embedding providers, with no artifact-backed malicious behavior found.
Install this only if you want OpenClaw conversations to be remembered automatically. Use a local/private Qdrant and local embeddings for sensitive content, or disable autoCapture/autoRecall and review hook permissions if you do not want conversation text stored or sent to an external embedding provider.
SkillSpector was not run because this plugin release contains no bundled skills.
Detected: suspicious.env_credential_access
if (process.env.OLLAMA_HOST || process.env.OLLAMA_BASE_URL) return "ollama";
if (process.env.OLLAMA_HOST || process.env.OLLAMA_BASE_URL) return "ollama"