Back to plugin

Security audit

Memory LanceDB

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent long-term memory plugin that stores and recalls user-approved memory data, with the sensitive behavior disclosed and scoped to its purpose.

Install only if you want OpenClaw to keep a persistent, searchable memory database. Review whether auto-capture should be enabled, which embedding provider or API key is configured, and where dbPath/storageOptions point, especially if using a remote storage endpoint.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.dynamic_code_execution, suspicious.env_credential_access

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
dist/.setup/dist-A24Sj2xJ.mjs:84
Evidence
return __require("child_process").execSync("ldd --version", { encoding: "utf8" }).includes("musl");

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
dist/.setup/dist-A24Sj2xJ.mjs:7696
Evidence
transformers = await eval("import(\"@huggingface/transformers\")");

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
dist/.setup/dist-A24Sj2xJ.mjs:90
Evidence
if (process.env.NAPI_RS_NATIVE_LIBRARY_PATH) try {