ClawAudit verdict
synthetic-supermemory
Accesses credentials AND writes files
The skill accesses credentials and installs packages, which could be a concern if not properly secured.
Automated static analysis โ not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
What it does
These are capability combinations: each listed behavior occurs in the skill, but ClawAudit detects co-occurrence โ it does not verify that one flows into another. Read the code to confirm a live chain.
Accesses credentials AND writes files โ may persist stolen credentials locally
LLM02 ยท LLM06 ยท ASI03
Permission integrity
package_install
Findings (2)
Accesses sensitive environment variables
references/api.md ยท code ยท process.env.SUPERMEMORY_API_KEY
Node http/https module โ low-level network access
scripts/scribe.js ยท prose ยท downgraded ยท require('https')
Permissions & capabilities
Requires 2 environment variables. (2 sensitive: SUPERMEMORY_API_KEY, OPENAI_API_KEY). Requires 1 system binary.
credential_accesspackage_installfile_write Thanks โ recorded.