Memory compression system for Claude Code - persist context across sessions
- capability exposure inferred + 35
- tool safety inferred + 12
- trust mitigators mixed − 8
inferred mixed
The A–E grade is our heuristic synthesis — a "review this" prompt, not a verdict. Each factor is tagged by what backs it: attested (a verifiable record), reported (a third party's claim), or inferred (our own heuristic, e.g. permissions). See methodology.
graded 5m ago · see ecosystem CVEs →
- C · 54 → C · 39
- C · 55 → C · 54
- C · 54 → C · 55
- C · 41 → C · 54
No known CVEs for this server.
- high dangerous code
dynamic exec: new Function() · suspicious bundled script in 1 file(s)
analyzed v13.15.0 · analyzer v32 · 13h ago
skills & prompt files 20
- skill package/openclaw/SKILL.md
- skill package/plugin/skills/babysit/SKILL.md
- skill package/plugin/skills/cloud-sync/SKILL.md
- skill package/plugin/skills/design-is/SKILL.md
- skill package/plugin/skills/do/SKILL.md
- skill package/plugin/skills/how-it-works/SKILL.md
- skill package/plugin/skills/knowledge-agent/SKILL.md
- skill package/plugin/skills/learn-codebase/SKILL.md
- skill package/plugin/skills/make-plan/SKILL.md
- skill package/plugin/skills/mem-search/SKILL.md
- skill package/plugin/skills/mode-creator/SKILL.md
- skill package/plugin/skills/oh-my-issues/SKILL.md
- skill package/plugin/skills/pathfinder/SKILL.md
- skill package/plugin/skills/smart-explore/SKILL.md
- skill package/plugin/skills/standup/SKILL.md
- skill package/plugin/skills/timeline-report/SKILL.md
- skill package/plugin/skills/version-bump/SKILL.md
- skill package/plugin/skills/weekly-digests/SKILL.md
- skill package/plugin/skills/what-the/SKILL.md
- skill package/plugin/skills/wowerpoint/SKILL.md
danger signals8
- dynamic code execution new Function() package/dist/npx-cli/index.js :1134
r(){if(r.count++>KU){let n;try{n=t.read=new Function("r","return function(){return "+(je.freezeData?"Object.freeze":"")+"({"+t.map(o=>o==="__proto__"?"__proto_:r()":joe.test(o)?o+":r()":"["+JSON.strin - suspicious endpoint us.i.posthog.com (telemetry)
expected for this server's purpose
package/dist/npx-cli/index.js :101
32N9qEiU6qhutZEiu6LLfRpXfTbLM9MLaG",I3="https://us.i.posthog.com";_3=["version","os","os_version","is_wsl","arch","runtime","locale","ide","provider","runtime_mode","install_method","claude_code_versi - suspicious endpoint api.telegram.org package/openclaw/src/index.ts :468
const response = await fetch(`https://api.telegram.org/bot${botToken}/sendMessage`, { - suspicious endpoint us.i.posthog.com (telemetry)
expected for this server's purpose
package/plugin/scripts/transcript-watcher.cjs :16
32N9qEiU6qhutZEiu6LLfRpXfTbLM9MLaG",Yn="https://us.i.posthog.com";function tr(){return process.env.CLAUDE_MEM_TELEMETRY_KEY||Gn}function rr(){return process.env.CLAUDE_MEM_TELEMETRY_HOST||Yn}var Kn=[" - suspicious endpoint us.i.posthog.com (telemetry)
expected for this server's purpose
package/plugin/scripts/worker-service.cjs :28
2N9qEiU6qhutZEiu6LLfRpXfTbLM9MLaG",Sde="https://us.i.posthog.com";Ede=["version","os","os_version","is_wsl","arch","runtime","locale","ide","provider","runtime_mode","install_method","claude_code_vers - suspicious endpoint api.telegram.org package/plugin/skills/mode-creator/scripts/configure-telegram.mjs :107
const response = await fetch(`https://api.telegram.org/bot${token}/${method}`, { - suspicious endpoint t.me package/plugin/skills/mode-creator/scripts/configure-telegram.mjs :170
console.log(`Open https://t.me/${bot.username}, press Start, and send any message.`); - suspicious bundled script suspicious bundled script package/openclaw/install.sh :419
if ! curl -fsSL https://bun.sh/install | bash; then
Heuristic, inferred signals — false positives (legitimately powerful tools, forks, language ports) are expected. Treat each as "review this", not a verdict. See the ecosystem-wide picture on the security hub, or the fleet security of thedotmack.