Back to plugin

Security audit

Nowledge Mem

Security checks for vulnerabilities and agentic risk

Overview

This memory plugin is coherent, but it needs review because it can persist and search normal OpenClaw conversations by default across a shared memory system.

Install only if you want OpenClaw to participate in Nowledge Mem as a long-term, cross-tool memory layer. Review whether default conversation capture is acceptable; use sessionDigest=false for manual-only memory, keep remote apiUrl/apiKey settings scoped to a server you trust, and use the skip marker or capture exclusions for sessions that should not be retained.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly says to save proactively and describes a cross-AI, cross-source memory store, but it does not require any user-facing notice, consent, or retention boundary. This creates a real privacy and security risk because sensitive conversation content, preferences, plans, or personal details may be retained and linked across tools without the user's informed expectation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation guidance is very broad and covers many common conversational patterns such as reminders, prior work, plans, and decisions. In a memory skill that can search across multiple sources and proactively save data, over-triggering can cause unnecessary access to sensitive historical context or persistence of data when the user did not clearly intend to use long-term memory.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.