vector-memory Security Audit Report
vector-memory is an AI agent skill, created by bluepointdigital and published at openclaw/skills. ClawSecure audited vector-memory across 15 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 0/100 (High Risk). The 15 findings concentrate in Malicious Code, Code Injection and Policy Violation, including Detects system manipulation, privilege escalation, and destructive file... and Attempts to access sensitive file: MEMORY.md. 13 were rated high or critical severity.
Is vector-memory safe?
ClawSecure audited vector-memory and assigned a security score of 0/100 (High Risk), identifying 15 findings across Malicious Code and Code Injection. Review the findings below before installing.
What did ClawSecure find in vector-memory?
ClawSecure identified 15 findings in vector-memory, concentrated in Malicious Code, Code Injection and Policy Violation. 13 were rated high or critical severity. The most severe include Detects system manipulation, privilege escalation, and destructive file... and Attempts to access sensitive file: MEMORY.md.
How was vector-memory audited?
ClawSecure ran vector-memory through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 15 files from openclaw/skills.
What does a score of 0 mean?
ClawSecure assigned vector-memory a security score of 0/100, placing it in the High Risk range. This is driven by 15 findings led by Malicious Code that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).
Audit Findings for vector-memory
ClawSecure detected 15 security findings in vector-memory, spanning Malicious Code, Code Injection, Policy Violation and Unauthorized Tool Use.
- high · Detects system manipulation, privilege escalation, and destructive file.... Unauthorized Tool Use finding detected in
install.sh:59. - high · Attempts to access sensitive file: MEMORY.md. Malicious Code finding detected in
AGENTS.md. - high · Attempts to access sensitive file: MEMORY.md. Malicious Code finding detected in
MEMORY_STRUCTURE.md. - high · Attempts to access sensitive file: MEMORY.md. Malicious Code finding detected in
README.md. - high · Attempts to access sensitive file: MEMORY.md. Malicious Code finding detected in
SKILL.md. - high · Attempts to access sensitive file: MEMORY.md. Malicious Code finding detected in
README.md. - high · Attempts to access sensitive file: MEMORY.md. Malicious Code finding detected in
skill.json. - high · Attempts to access sensitive file: MEMORY.md. Malicious Code finding detected in
memory.js. - high · Attempts to access sensitive file: MEMORY.md. Malicious Code finding detected in
integration.md. - high · Attempts to access sensitive file: MEMORY.md. Malicious Code finding detected in
smart_memory.js. - high · Attempts to access sensitive file: MEMORY.md. Malicious Code finding detected in
vector_memory_local.js. - high · Potentially dangerous code pattern detected: curl.*\|.*sh. Code Injection finding detected in
README.md.
Showing the 12 highest-severity of 15 findings. The full interactive list appears below.
3-Layer Audit Protocol
Security Recommendations for vector-memory
Audit external network connections
Eliminate dynamic code execution
Resolve policy violations
Related Security Research
ClawHavoc Explained: The Malware Family Targeting AI Agents→Beyond Static Scans: Why ClawSecure Verifies Agentic Intent→Related AI Agent Security Audits
Scanned on February 7, 2026. vector-memory is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.