← Back to Scanner

memU Security Audit Report

🔭 Continuously monitored by ClawSecure Watchtower
Source:
SHA-256:

memU is an AI agent skill, created by NevaMind-AI and published at NevaMind-AI/memU. ClawSecure audited memU across 76 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 0/100 (High Risk). The 41 findings concentrate in Malicious Code, Supply Chain Attack and Code Injection, including Suspicious Pattern: spawnSync( and Suspicious Pattern: spawnSync(. 20 were rated high or critical severity.

Is memU safe?

ClawSecure audited memU and assigned a security score of 0/100 (High Risk), identifying 41 findings across Malicious Code and Supply Chain Attack. Review the findings below before installing.

What did ClawSecure find in memU?

ClawSecure identified 41 findings in memU, concentrated in Malicious Code, Supply Chain Attack and Code Injection. 20 were rated high or critical severity. The most severe include Suspicious Pattern: spawnSync( and Suspicious Pattern: spawnSync(.

How was memU audited?

ClawSecure ran memU through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 76 files from NevaMind-AI/memU.

What does a score of 0 mean?

ClawSecure assigned memU a security score of 0/100, placing it in the High Risk range. This is driven by 41 findings led by Malicious Code that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).

Audit Findings for memU

ClawSecure detected 41 security findings in memU, spanning Malicious Code, Supply Chain Attack, Code Injection and Command Injection.

Showing the 12 highest-severity of 41 findings. The full interactive list appears below.

3-Layer Audit Protocol

Security Recommendations for memU

Audit external network connections
memU connects to external endpoints. Verify every outbound connection goes to a trusted destination. Unauthorized callbacks are a primary indicator of ClawHavoc malware and data exfiltration. ClawSecure's proprietary engine monitors for known malicious endpoints including C2 infrastructure.
Eliminate dynamic code execution
memU evaluates code at runtime (for example eval or dynamic exec). Remove dynamic evaluation of untrusted input, and where code generation is unavoidable, sandbox it and validate every input.
Harden command execution
memU constructs or runs system commands. Validate that commands are built only from trusted inputs, never pass user-controlled strings directly to a shell, and restrict execution to an allow-list of expected commands.

Related Security Research

ClawHavoc Explained: The Malware Family Targeting AI AgentsBeyond Static Scans: Why ClawSecure Verifies Agentic Intent

Related AI Agent Security Audits

gstackScore 0/100awesome-openclaw-skillsScore 0/100understand-anythingScore 0/10062ac696296b54aadScore 0/1006bc837afc1a86e89Score 0/100

Scanned on August 12, 2026. memU is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.

Start Your Free Scan