Security audit
XMemo for OpenClaw
Security checks across malware telemetry and agentic risk
Overview
This is a disclosed cloud memory plugin that stores and retrieves data through XMemo when configured, with sensitive behavior mostly opt-in and documented.
Install only if you want OpenClaw to use XMemo as a cloud-backed memory provider. Use environment SecretRefs for credentials in shared or production environments, keep autoCapture off unless you explicitly want automatic memory writes, narrow readBucket/readScope when broad cross-agent recall is not desired, and use hard delete, redact, audit, ledger, and snapshot restore tools only with deliberate user intent.
SkillSpector
SkillSpector was not run because this plugin release contains no bundled skills.
VirusTotal
61/61 vendors flagged this plugin as clean.
Static analysis
No suspicious patterns detected.
