memU is an AI agent skill, created by NevaMind-AI and published at NevaMind-AI/memU. ClawSecure audited memU across 76 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 0/100 (High Risk). The 41 findings concentrate in Malicious Code, Supply Chain Attack and Code Injection, including Suspicious Pattern: spawnSync( and Suspicious Pattern: spawnSync(. 20 were rated high or critical severity.
Is memU safe?
ClawSecure audited memU and assigned a security score of 0/100 (High Risk), identifying 41 findings across Malicious Code and Supply Chain Attack. Review the findings below before installing.
What did ClawSecure find in memU?
ClawSecure identified 41 findings in memU, concentrated in Malicious Code, Supply Chain Attack and Code Injection. 20 were rated high or critical severity. The most severe include Suspicious Pattern: spawnSync( and Suspicious Pattern: spawnSync(.
How was memU audited?
ClawSecure ran memU through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 76 files from NevaMind-AI/memU.
What does a score of 0 mean?
ClawSecure assigned memU a security score of 0/100, placing it in the High Risk range. This is driven by 41 findings led by Malicious Code that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).
Audit Findings for memU
ClawSecure detected 41 security findings in memU, spanning Malicious Code, Supply Chain Attack, Code Injection and Command Injection.
- critical · Suspicious Pattern: spawnSync(. Command Injection finding detected in
npm/bin/memu.js:17. - critical · Suspicious Pattern: spawnSync(. Command Injection finding detected in
npm/bin/memu.js:22. - critical · Suspicious Pattern: spawnSync(. Command Injection finding detected in
npm/bin/memu.js:40. - high · Attempts to access sensitive file: MEMORY.md. Malicious Code finding detected in
CHANGELOG.md. - high · Attempts to access sensitive file: SOUL.md. Malicious Code finding detected in
README.md. - high · Attempts to access sensitive file: MEMORY.md. Malicious Code finding detected in
README.md. - high · Attempts to access sensitive file: MEMORY.md. Malicious Code finding detected in
0004-workspace-memorize-and-memory-file-system.md. - high · Attempts to access sensitive file: MEMORY.md. Malicious Code finding detected in
0006-from-memory-item-category-to-tracked-workspace-memorization.md. - high · Attempts to access sensitive file: MEMORY.md. Malicious Code finding detected in
0007-three-independent-memory-lines-wiki-graph.md. - high · Attempts to access sensitive file: MEMORY.md. Malicious Code finding detected in
0008-two-integration-surfaces-hooks-and-api.md. - high · Attempts to access sensitive file: SOUL.md. Malicious Code finding detected in
0010-multi-host-adapters.md. - high · Attempts to access sensitive file: SOUL.md. Malicious Code finding detected in
0011-generic-host-adapter.md.
Showing the 12 highest-severity of 41 findings. The full interactive list appears below.
3-Layer Audit Protocol
Security Recommendations for memU
Audit external network connections
Eliminate dynamic code execution
Harden command execution
Related Security Research
ClawHavoc Explained: The Malware Family Targeting AI Agents→Beyond Static Scans: Why ClawSecure Verifies Agentic Intent→Related AI Agent Security Audits
Scanned on August 12, 2026. memU is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.