ClawAudit verdict
membase
unibase-membase
The skill manages agent memory backups and restores with Membase. The approach seems secure and legitimate.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Permission integrity
credential_access
Findings (3)
Dynamic import() — loads module at runtime
membase.ts · prose · downgraded · import('
References agent memory files
SKILL.md · prose · downgraded · MEMORY.md
Accesses sensitive environment variables
commands/backup.ts · prose · downgraded · process.env.MEMBASE_BACKUP_PASSWORD
Permissions & capabilities
No declared permissions — minimal attack surface.
network_incredential_access Is this flag fair?
Thanks — recorded.