Reddit user nintavur_wings alleges claude-mem polls Claude Code login tokens every 30 seconds through dynamically compiled PowerShell/C# calls to Windows CredRead, triggering Kaspersky detection and raising a credential-handling concern for the memory component.
state: seedheat: mediumuncertainty: mediumknownscott: lowagent-memory agentic-security credential-securitynintavur_wingsclaude-memKaspersky
What is this?
claude-mem is presented in the case as a memory component for Claude Code; the supplied GitHub result locates its repository under thedotmack/claude-mem and reports unexpected PowerShell pop-ups on Windows 11. The case attributes to Reddit user nintavur_wings an allegation that it reads Claude Code login tokens every 30 seconds using dynamically compiled PowerShell/C# calls to Windows CredRead, triggering Kaspersky. The supplied search snippets do not independently establish that mechanism, polling interval, or detection, and the pop-up report alone does not establish credential misuse.
Why it matters to Scott
The concern illustrates Scott’s existing credential-separated execution position in Sandboxed Execution and SiloOS, rather than challenging or extending it; the radar’s claude-code-plaintext-oauth-tokens case is related but does not track this same allegation. The supplied evidence neither independently verifies the alleged polling and Kaspersky detection nor establishes that Scott uses claude-mem, so it does not yet warrant a change to his builds or arguments.
ip:concept.sandboxed-executionip:framework.siloosradar:claude-code-plaintext-oauth-tokensradar:concept.credential-security
queries asked of Scott's wikis
- agent memory plugin trust boundaries
- coding agent extensions credential access token handling
- Claude Code memory integrations dependency audits
- Windows agent tooling PowerShell security
- persistent agent background processes least privilege
Measured heat
now 0 pts/hpeak 0 pts/hcomments 0/hpeers p0momentum: steady1 platformsage 677h
points/hour across evidence · reading as of 2026-10-12 02:59:37.977291+11:00 · deterministic, not a model opinion
How the heat travelled
pace: p69 vs 1032 stories at the 336h mark (now 677h old) — ahead of halv-coding-token-savings (1.0x), behind nari-qwen3-speech-ga (1.0x)
Evidence (1) — ⭐ canonical anchor
Interpretation history
2026-09-13T12:30:57Z
grounded: known/low — The concern illustrates Scott’s existing credential-separated execution position in Sandboxed Execution and SiloOS, rather than challenging or extending it; the
2026-09-13T12:27:02Z
case created — The report identifies a specific inspectable credential-access mechanism, distinct from the existing token-theft episode, without establishing malicious intent or exfiltration.
Decision trace
- 10-11 23:18review_dormant28 days without material information; scheduled checks stopped
- 09-14 11:22review_screenThe changes add opinions and a warning about random plugins but provide no new factual evidence, implementation result, contradiction, or access change.
- 09-14 11:21sensor_dirtycomment_update
- 09-14 04:42review_screenThe new comments repeat the existing credential-access concern and add dismissive commentary without new evidence, implementation results, contradiction, or a consequential change.
- 09-14 04:21sensor_dirtycomment_update
- 09-13 22:30groundThe concern illustrates Scott’s existing credential-separated execution position in Sandboxed Execution and SiloOS, rather than challenging or extending it; the radar’s claude-code-plaintext-oauth-tok
- 09-13 22:27createThe report identifies a specific inspectable credential-access mechanism, distinct from the existing token-theft episode, without establishing malicious intent or exfiltration.