This report was generated in Chinese. Some content may be in Chinese.
Trusted — Risk Score 5/100
Last scan:4 hr ago Rescan
5 /100
human-like-memory
Long-term memory for conversations: recall past discussions, save important info, search memories
合法的长期记忆技能,代码结构清晰,功能与文档完全一致,仅将对话数据发送到声明的远程API服务进行记忆存储和检索
Skill Namehuman-like-memory
Duration48.1s
Enginepi
ClawHub Human-Like Memory v0.7.4 by humanlike2026
ClawHub Verdict Suspicious dangerous_execpotential_exfiltration
Safe to install
可安全使用。建议验证 plugin.human-like.me 服务提供商的可靠性

Findings 2 items

Severity Finding Location
Info
配置文件读取 Sensitive Access
代码读取 ~/.openclaw/secrets.json 和 ~/.openclaw/skills/ 目录下的配置文件,用于获取API密钥和技能配置。这在 SKILL.md 中未明确声明,但属于合理的配置管理行为。
const SECRETS_FILE = join(OPENCLAW_DIR, 'secrets.json');
const CONFIG_FILE = join(OPENCLAW_DIR, 'skills', 'human-like-memory', 'config.json');
→ 建议在 SKILL.md 中明确声明配置文件读取行为
scripts/memory.mjs:24
Info
外部服务依赖 Supply Chain
技能依赖外部服务 plugin.human-like.me 进行记忆存储,该服务由 'hanlaomo' 开发和托管,URL 在多个文件中硬编码。
baseUrl: ... || 'https://plugin.human-like.me'
→ 建议确认服务提供商的可靠性和隐私政策
scripts/memory.mjs:152
ResourceDeclaredInferredStatusEvidence
Network READ READ ✓ Aligned scripts/memory.mjs:180-200
Filesystem NONE READ ✓ Aligned scripts/memory.mjs:24-26 读取配置和密钥文件
Environment READ READ ✓ Aligned scripts/memory.mjs:41-45
Shell NONE NONE 无shell执行
4 findings
🔗
Medium External URL 外部 URL
https://gitlab.ttyuyin.com/personalization_group/human-like-mem-openclaw-skill.git
README.md:23
🔗
Medium External URL 外部 URL
https://plugin.human-like.me
README.md:33
🔗
Medium External URL 外部 URL
https://www.npmjs.com/package/human-like-mem-openclaw-plugin
README.md:151
🔗
Medium External URL 外部 URL
https://clawhub.dev/skills/human-like-memory
scripts/memory.mjs:152

File Tree

7 files · 48.0 KB · 1722 lines
JavaScript 2f · 984L Markdown 3f · 464L Shell 1f · 174L JSON 1f · 100L
├─ 📁 scripts
│ ├─ 📜 memory.mjs JavaScript 733L · 19.8 KB
│ └─ 🔧 setup.sh Shell 174L · 5.4 KB
├─ 📁 test
│ └─ 📜 test-memory.mjs JavaScript 251L · 7.8 KB
├─ 📝 README_EN.md Markdown 105L · 2.8 KB
├─ 📝 README.md Markdown 155L · 4.7 KB
├─ 📋 skill.json JSON 100L · 2.8 KB
└─ 📝 SKILL.md Markdown 204L · 4.8 KB

Security Positives

✓ 代码结构清晰,无混淆或隐藏逻辑
✓ 功能实现与 SKILL.md 文档描述完全一致
✓ 无恶意代码模式:无base64解码、无eval、无反向shell、无凭证外泄
✓ 配置文件和凭证读取仅用于API认证,用途合理
✓ Upgrade通知机制是合法的版本检查功能
✓ 包含完整的测试套件,代码质量良好
✓ 无远程脚本执行或动态代码下载