Is clawdbot51-oss/supermemory safe?
Use with caution. clawdbot51-oss/supermemory is not clearly unsafe, but the audit flagged risks to review before you install it. Oathe's behavioral security audit gave the supermemory skill by clawdbot51-oss a trust score of 72/100 with 3 findings (1 high).
https://github.com/openclaw/skills/tree/main/skills/clawdbot51-oss/supermemory
Is clawdbot51-oss/supermemory safe to install?
The SuperMemory skill provides legitimate functionality for storing and retrieving memories via an external API, but contains a significant security flaw with a hardcoded API key exposed in the documentation. While the skill's core functionality appears benign, the credential exposure creates serious security and privacy risks.
What security issues were found in clawdbot51-oss/supermemory?
Category Scores
Findings (3)
HIGH Hardcoded API Key Exposed -50 ▶
The SKILL.md file contains a hardcoded SuperMemory API key (sm_oiZHA2HcwT4tqSKmA7cCoK_opSRFViNFNxbYqjkjpVNfjSPqQWCNoOBAcxKZkKBfRVVrEQDVxLWHJPvepxqwEPe) in plain text as an example. This appears to be a real API key that could be used by anyone accessing the skill documentation, potentially resulting in unauthorized usage, data access, or charges to the original account owner.
MEDIUM External Data Transmission -10 ▶
The skill scripts make HTTP requests to api.supermemory.ai endpoints, sending user data including memory content and search queries. While this is the stated functionality, it creates a pathway for data exfiltration if the external service is compromised or malicious.
LOW Shell Script Execution -10 ▶
The skill contains executable bash scripts that run with user privileges. While the scripts appear to perform legitimate functions, they do execute system commands and make network requests.
Should I install clawdbot51-oss/supermemory?
Oathe's verdict for clawdbot51-oss/supermemory is CAUTION with a trust score of 72/100. Recommendation: Install with caution.