openclaw-memx-memory-plugin

Warn

Audited by Socket on Sep 12, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose and capabilities mostly align for a memory plugin, and there is no clear credential theft or hidden exfiltration. However, the install trust chain is weak and publisher identity is inconsistent, with a personal GitHub repo used as the core plugin source plus unpinned pip dependencies; that makes the skill medium-high risk despite otherwise coherent functionality.

Confidence: 88%Severity: 72%
Audit Metadata
Analyzed At
Sep 12, 2026, 06:52 PM
Package URL
pkg:socket/skills-sh/reason-machines%2Fhermes-skills%2Fopenclaw-memx-memory-plugin%2F@bfa155552e9f5ac2ac0cb2486cd063e93e5b24240d776ebb923197bff0b5fc22
Security Audit — socket — openclaw-memx-memory-plugin