← Back to Scanner

memU Security Audit Report

🔭 Continuously monitored by ClawSecure Watchtower
Source:
SHA-256:

memU is an AI agent skill, created by NevaMind-AI and published at NevaMind-AI/memU. ClawSecure audited memU across 71 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 0/100 (High Risk). The 22 findings concentrate in Malicious Code, Command Injection and Code Injection, including Suspicious Pattern: spawnSync( and Suspicious Pattern: spawnSync(. 14 were rated high or critical severity.

Is memU safe?

ClawSecure audited memU and assigned a security score of 0/100 (High Risk), identifying 22 findings across Malicious Code and Command Injection. Review the findings below before installing.

What did ClawSecure find in memU?

ClawSecure identified 22 findings in memU, concentrated in Malicious Code, Command Injection and Code Injection. 14 were rated high or critical severity. The most severe include Suspicious Pattern: spawnSync( and Suspicious Pattern: spawnSync(.

How was memU audited?

ClawSecure ran memU through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 71 files from NevaMind-AI/memU.

What does a score of 0 mean?

ClawSecure assigned memU a security score of 0/100, placing it in the High Risk range. This is driven by 22 findings led by Malicious Code that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).

Audit Findings for memU

ClawSecure detected 22 security findings in memU, spanning Malicious Code, Command Injection, Code Injection and Unauthorized Tool Use.

Showing the 12 highest-severity of 22 findings. The full interactive list appears below.

3-Layer Audit Protocol

Security Recommendations for memU

Audit external network connections
memU connects to external endpoints. Verify every outbound connection goes to a trusted destination. Unauthorized callbacks are a primary indicator of ClawHavoc malware and data exfiltration. ClawSecure's proprietary engine monitors for known malicious endpoints including C2 infrastructure.
Harden command execution
memU constructs or runs system commands. Validate that commands are built only from trusted inputs, never pass user-controlled strings directly to a shell, and restrict execution to an allow-list of expected commands.
Eliminate dynamic code execution
memU evaluates code at runtime (for example eval or dynamic exec). Remove dynamic evaluation of untrusted input, and where code generation is unavoidable, sandbox it and validate every input.

Related Security Research

ClawHavoc Explained: The Malware Family Targeting AI AgentsBeyond Static Scans: Why ClawSecure Verifies Agentic Intent

Related AI Agent Security Audits

62ac696296b54aadScore 0/1006bc837afc1a86e89Score 0/10062ac696296b54aadScore 0/100openclaw-master-skillsScore 0/1006bc837afc1a86e89Score 0/100

Scanned on July 22, 2026. memU is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.

Start Your Free Scan