Real Skill packageSource verifiedClawHub registry

Openclaw Memory Toolkit

Hybrid memory pipeline for OpenClaw agents — extraction, archiving, temporal decay scoring, consolidation, and hybrid search (FTS5 + sqlite-vec + RRF). Six standalone Python scripts, local-first, zero external API dependencies. The only memory skill on ClawHub with R

Identity and source

Publisher attributionMisterMiJarvisregistry owner unverified by skillvetai
Functional categoryAgent Engineering, Security & Governanceautomatically inferred · 66% rule confidence
Package forminstruction with code12 recorded files
Canonical sourceClawHub registryclawhub:mistermijarvis:memory-toolkit
Open canonical source ↗

Platform declarations

These states come from the source or distribution context. None of the entries below are SkillVetAI compatibility test results.

OpenClawnative officialProvenance: registry distribution

Independent structural checks

These checks parse the fixed package against dated platform rules. They do not execute the Skill or verify task behavior.

Claude Codeissues found
Checker 0.1.0 · agent-skills-2026-08-13+claude-code-docs-2026-08-13 · 8/23/2026.claude/skills/<skill-name>
1 structural issue
  • error: SKILL.md does not contain a complete YAML frontmatter envelope. SKILL.md

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

OpenAI Codexissues found
Checker 0.1.0 · agent-skills-2026-08-13+codex-docs-2026-08-13 · 8/23/2026.agents/skills/<skill-name>
1 structural issue
  • error: SKILL.md does not contain a complete YAML frontmatter envelope. SKILL.md

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

OpenClawissues found
Checker 0.1.0 · agent-skills-2026-08-13+openclaw-docs-2026-08-13 · 8/23/2026skills/<skill-name>
1 structural issue
  • error: SKILL.md does not contain a complete YAML frontmatter envelope. SKILL.md

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

Installation and inspection

This command is recorded from the source ecosystem and resolves the registry's latest release. The fixed release shown on this page should be inspected before adoption.

clawhub install @mistermijarvis/memory-toolkit
clawhub inspect @mistermijarvis/memory-toolkit --version 2.1.1

Security evidence

SkillVetAI static result: medium signal

This automated, non-executing scan is bound to this release hash. It is not a safety certification and may contain false positives or false negatives.

Status
completed
Coverage
full text content
Files
12 / 12 inspected as text
Checked
8/23/2026, 2:01:35 AM
Scanner
0.1.3
Policy
1.0.3
1 automated finding
mediumSKILL.md has no parseable YAML frontmatterSKILL.md:1 · confidence 100%missing frontmatter
5 inferred permission indicators
  • shell execution — automatically inferred
  • network access — automatically inferred
  • filesystem read — automatically inferred
  • filesystem write — automatically inferred
  • credential access — automatically inferred
3 dependency and API indicators
  • api: clawhub.ai
  • api: github.com
  • api: www.w3.org
External clawhub result: suspicious

This is registry-supplied evidence for the recorded release, not an independent SkillVetAI scan. Check the canonical source for the full report, scanner versions, scope, and current moderation state.

Evidence checked
8/22/2026, 6:02:51 PM
Release binding
Matches this record
  • skillspector: suspicious
  • llm: suspicious

Recorded files

The catalog stores hashes and an inventory summary for change detection. It does not republish the package contents.

Package content hashsha256:318c105b69c516adc08ff5996dc49de775b4516e0770d60a419255af46bbb325
Show up to 12 recorded paths
  • .gitignore
  • auto_archive.py
  • CHANGELOG.md
  • consolidate_advisor.py
  • hybrid-search/hybrid_search.py
  • hybrid-search/run_tests.py
  • hybrid-search/schema.sql
  • memory-health.py
  • README.md
  • scoring.py
  • skill-card.md
  • SKILL.md

Source changelog

Sensitive Data Purge Deleted: results/*.json (11 files), results/*.svg (9 files) Deleted: hybrid-search/FULL_INDEX_REPORT.md, hybrid-search/test_results.json, hybrid-search/agent_memory.db Deleted: hybrid-search-proto/ (entire prototype folder) Deleted: __pycache__/ (all .pyc files) All PII removed: personal names, company names, secret paths, domain names, project names .gitignore Hardened Added: *.svg, eval_output/, *.log, *.pyc, hybrid-search-proto/, .secrets/ Subprocess.run Hardening PII query replaced with anonymized fixture (project alpha configuration) All script paths validated with Path.resolve().is_relative_to(WORKSPACE) — prevents path traversal No environment variable injection in subprocess calls — fixed argument lists only Scope Confinement (anti skill enumeration) hybrid_search.py: no longer globs skills/*/SKILL.md — only indexes its own SKILL.md Personal files excluded f…

Release security diff

mediumCompared fixed releases 1.0.5 and 2.1.1; 0 finding and 0 permission indicators were added.

Both fixed releases were scanned under the current scanner and policy, so finding, permission and dependency changes are available.

Change reasons and limitations
  • file surface changed
  • content hash changed

Observed release history

These older immutable releases were observed by prior successful syncs. They remain recorded when a newer release becomes current.

1.0.58/18/2026sha256:6a348ba9058f82070195a904f9b885e06b2044570eeaafc5ba71bd2375e6b6a3
1.0.38/18/2026sha256:1a0856dd21e74425c9c47012e72a65ce4522b5cdcba380c25e4a7694e23844dc
1.0.08/18/2026sha256:16f7b62844e2a6330f222bd1fb842c91e5661b271ffd732269062d516ee2e4b2
0.1.08/18/2026sha256:76fad3d40ae2f10897c646c0fc554acdcc4d44ce7c9e9cf8791669e657c27120