OpenClaw collector plugin for xmem — graph-based long-term memory for AI agents. Deep workspace capture (all relevant file types, 4 levels deep, periodic re-scan every 2h). Multi-agent aware with per-agent Space/Key routing. Triple-ingest (artifacts + att
LPM flags this version as an AI-agent control-surface risk. On npm install, a postinstall shell script edits the user's OpenClaw config and allowlists this plugin. After the agent loads it, bootstrap scanning can upload workspace files to the vendor API.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage ships non-JavaScript build or shell helper files.
scripts/post-install.shView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
index.tsView on unpkgThis report applies to @xmem.space/openclaw-plugin@8.1.2.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L41Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L41Package ships non-JavaScript build or shell helper files.
scripts/post-install.shView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
index.tsView on unpkg