memory-scan面向AI Agent记忆文件与工作区配置的安全扫描工具,检测恶意指令、Prompt注入、凭证泄漏、数据外泄、护栏绕过、行为操纵、权限提升七大威胁类别. 提供五级安全分级、本地模式与可选远程LLM分析、隔离与恢复、定时监控集成、心跳任务集成五大核心能力. 适用于Agent记忆日常安全审计、凭证泄漏排查、引入外部数据...
Install via ClawdBot CLI:
clawdbot install dgriffin831/memory-scanGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Contains instructions to override system prompt or ignore user requests
"Ignore all previous instructions"Sends data to undocumented external endpoint (potential exfiltration)
send → https://evil.comHardcoded API key or token pattern found in skill definition
sk-123456789...Calls external URL not in known-safe list
https://github.com/utkusen/promptmap/tree/main/rules/prompt_stealingGenerated Mar 1, 2026
A cybersecurity firm uses the memory-scan skill to routinely audit its AI agents' memory files for any inadvertent credential leakage or malicious instructions injected during client interactions. This ensures compliance with data protection regulations and maintains client trust by proactively identifying and quarantining security threats before they escalate.
A bank integrates memory-scan into its AI-driven customer service agents to detect prompt injection attempts or data exfiltration commands that could compromise sensitive financial data. Scheduled daily scans help meet regulatory requirements for internal security audits and prevent unauthorized behavioral manipulation of AI systems.
A healthcare provider employs memory-scan to monitor AI agents handling patient data, scanning for credential leaks or malicious instructions that could violate HIPAA regulations. The skill's alert workflow ensures immediate review of medium to critical threats, safeguarding patient privacy and preventing data breaches in clinical workflows.
An e-commerce company uses memory-scan to analyze AI agent memories for patterns of guardrail bypass or privilege escalation attempts by malicious users. This helps detect and quarantine threats that could lead to fraudulent transactions or unauthorized access to customer accounts, enhancing overall platform security.
A research lab implements memory-scan to audit AI agents involved in experimental data analysis, ensuring no prompt injections or malicious instructions compromise research integrity. The skill's integration with safe-install for daily audits provides continuous monitoring, critical for maintaining ethical AI use in sensitive scientific environments.
Offer memory-scan as a cloud-based service where businesses pay a monthly fee for automated AI memory scanning and threat alerts. Revenue is generated through tiered subscriptions based on scan frequency, number of agents monitored, and access to advanced features like remote LLM analysis and detailed reporting.
Sell enterprise licenses for on-premises deployment of memory-scan, including custom integration with existing AI systems and dedicated support. Revenue comes from one-time license fees plus annual maintenance contracts for updates, priority support, and training services tailored to large organizations.
Provide a free version of memory-scan with basic local scanning capabilities, while charging for premium features such as scheduled monitoring, advanced LLM analysis, and integration with third-party security tools. Revenue is generated through upgrades and add-ons for businesses needing enhanced security and automation.
💬 Integration Tip
Integrate memory-scan with existing cron jobs or CI/CD pipelines for automated daily audits, and configure alert channels in OpenClaw to ensure immediate notification of threats without manual intervention.
Scored Apr 22, 2026
Uses known external API (expected, informational)
api.anthropic.comAI Analysis
The skill definition contains direct evidence of prompt poisoning ('Ignore all previous instructions'), credential harvesting (hardcoded API key pattern), and data exfiltration to an unauthorized external endpoint ('https://evil.com'). These are active threats that could compromise user security and override system safety.
Audited Apr 16, 2026 · audit v1.0
Manage and operate ClawSec Monitor v3.0, a MITM HTTP/HTTPS proxy that logs AI agent traffic, detects exfiltration and injection threats in real time.
Command-line security analyzer for ClawHub skills. Run analyze-skill.sh to scan SKILL.md files for malicious patterns, credential leaks, and C2 infrastructure before installation. Includes threat intelligence database with 20+ detection patterns.
Scan Clawdbot and MCP skills for malware, spyware, crypto-miners, and malicious code patterns before you install them. Security audit tool that detects data exfiltration, system modification attempts, backdoors, and obfuscation techniques.
577+ pattern prompt injection defense. Now with typo-tolerant bypass detection. TieredPatternLoader fully operational. Drop-in defense for any LLM application.
Security scanner for ClawHub skills. Vet third-party skills before installation — detect dangerous patterns, suspicious code, and risky dependencies.
Security audit and hardening for AI agents — credential hygiene, secret scanning, prompt injection defense, data leakage prevention, and privacy zones.