Real Skill packageSource verifiedClawHub registry

MemHub

使用 MemHub Protocol v0.1 管理用户明确指定的跨 Agent 记忆仓库。用于用户明确要求记住、检索、遗忘、导出上下文或配置 Git 同步时;读取可直接执行,持久写入、自动同步、OAuth、remote 修改和仓库创建必须来自当前用户的明确请求。

Identity and source

Publisher attributionTandyregistry owner unverified by skillvetai
Functional categoryAgent Engineering, Security & Governanceautomatically inferred · 70% rule confidence
Package forminstruction with code6 recorded files
Canonical sourceClawHub registryclawhub:cutd:memhub
Open canonical source ↗

Platform declarations

These states come from the source or distribution context. None of the entries below are SkillVetAI compatibility test results.

OpenClawnative officialProvenance: registry distribution

Independent structural checks

These checks parse the fixed package against dated platform rules. They do not execute the Skill or verify task behavior.

Claude Codepasses structure
Checker 0.1.0 · agent-skills-2026-08-13+claude-code-docs-2026-08-13 · 9/23/2026.claude/skills/memhub

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

OpenAI Codexpasses structure
Checker 0.1.0 · agent-skills-2026-08-13+codex-docs-2026-08-13 · 9/23/2026.agents/skills/memhub

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

OpenClawpasses structure
Checker 0.1.0 · agent-skills-2026-08-13+openclaw-docs-2026-08-13 · 9/23/2026skills/memhub

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

Installation and inspection

This command is recorded from the source ecosystem and resolves the registry's latest release. The fixed release shown on this page should be inspected before adoption.

clawhub install @cutd/memhub
clawhub inspect @cutd/memhub --version 0.4.10

Security evidence

SkillVetAI static result: no findings detected

This automated, non-executing scan is bound to this release hash. It is not a safety certification and may contain false positives or false negatives.

Status
completed
Coverage
full text content
Files
6 / 6 inspected as text
Checked
9/23/2026, 1:28:05 PM
Scanner
0.1.3
Policy
1.0.3
5 inferred permission indicators
  • shell execution — automatically inferred
  • network access — automatically inferred
  • filesystem read — automatically inferred
  • filesystem write — automatically inferred
  • credential access — automatically inferred
3 dependency and API indicators
  • api: clawhub.ai
  • api: gitee.com
  • api: github.com
External clawhub result: clean

This is registry-supplied evidence for the recorded release, not an independent SkillVetAI scan. Check the canonical source for the full report, scanner versions, scope, and current moderation state.

Evidence checked
9/22/2026, 2:34:59 AM
Release binding
Matches this record
  • vt: clean
  • skillspector: suspicious
  • llm: clean

Recorded files

The catalog stores hashes and an inventory summary for change detection. It does not republish the package contents.

Package content hashsha256:0bbffd956f242dd617e65305a4e1671f8d4a58520be8a1989fb7ca555e20ba4a
Show up to 6 recorded paths
  • permissions.json
  • README.md
  • scripts/memhub.py
  • skill-card.md
  • SKILL.md
  • templates/context-pack.md.j2

Source changelog

Security hardening: credentials moved outside the memory repo (0600 file in a 0700 dir, MEMHUB_SECRETS_DIR overridable, legacy in-repo copy migrated once), Gitee direct OAuth now generates and verifies an OAuth state to prevent account substitution, doctor is offline by default and only probes a broker with --network, and permissions.json declares filesystem, shell, network and credential boundaries.