Back to plugin

Security audit

Remnic OpenClaw Plugin

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Remnic memory plugin that stores and recalls conversation memory locally, with optional provider/model integrations that are described in its metadata and README.

Install only if you want Remnic to act as your OpenClaw memory layer. Review provider settings before use: conversation and memory excerpts can go to configured LLM providers unless routed through an approved gateway/local model path, and local memory/transcripts will persist on disk according to the plugin configuration.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

Detected: suspicious.potential_exfiltration

Sensitive-looking file read is paired with a network send.

Warn
Code
suspicious.potential_exfiltration
Location
dist/index.js:6528
Evidence
const store = JSON.parse(fs3.readFileSync(tokenStore.path, "utf8"));