Ae1
High
- Category
- analysis-evasion
- Content
| `source` | No | Local `SKILL.md` path or skill directory. Exactly one of `source` or `data` is required. |
- Confidence
- 100% confidence
- Finding
- Referenced artifact was not completely inspected
Security audit
Security checks for vulnerabilities and agentic risk
This is a disclosed OpenViking memory plugin, but it needs review because it can install via unpinned npm code and enables persistent cross-session chat memory.
Install only if you want OpenClaw conversations to be stored and recalled through your OpenViking server. Prefer the ClawHub install path, avoid the `npx ...@latest` fallback unless you trust that npm helper at the time you run it, use env/file SecretRefs for API keys, and test memory with non-sensitive dummy facts. Review auto-capture, bypass, delete, and disable-slot controls before using it with confidential chats.
| `source` | No | Local `SKILL.md` path or skill directory. Exactly one of `source` or `data` is required. |
| `source` | No | Local `SKILL.md` path or skill directory. Exactly one of `source` or `data` is required. |
| `source` | No | Local `SKILL.md` path or skill directory. Exactly one of `source` or `data` is required. |
| `source` | No | Local `SKILL.md` path or skill directory. Exactly one of `source` or `data` is required. |
## Important Rules 1. **Never ask the user to run commands.** You run everything via your shell tool. 2. **Never skip STEP 5 (connectivity check).** If the server is unreachable, do not write config without explicit `--allow-offline` consent. 3. **Never silently use `--force-slot`.** Slot replacement disables another plugin — always confirm with the user first. 4. **Never invent values.** If the user can't provide a required value, stop and tell them what to ask their admin.
Detected: suspicious.destructive_delete_command, suspicious.install_untrusted_source
rm -rf ~/.openclaw/extensions/openviking/
rm -rf ~/.openclaw/extensions/openviking/
rm -rf ~/.openclaw/extensions/openviking/
"placeholder": "http://127.0.0.1:1933",