Back to plugin

Security audit

memsearch — OpenClaw Plugin

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed persistent memory plugin that stores and recalls conversation summaries; its sensitive access is expected for that purpose.

Before installing, understand that this plugin will retain summaries of your conversations, may read original OpenClaw transcripts for recall, and inject recalled memories into future prompts. Review where .memsearch data is stored, disable autoCapture or autoRecall if you do not want automatic memory behavior, and avoid using shared MEMSEARCH_DIR locations for sensitive projects unless that sharing is intended.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
skills/memory-config/SKILL.md:170
Evidence
api_key = "[REDACTED]"