Back to skill

Security audit

ClawRAG - Self-hosted RAG & Memory

Security checks for vulnerabilities and agentic risk

Overview

The skill fits its stated RAG connector purpose, but it sends users through mutable Docker and npm setup paths that can execute changed third-party code without pinning or integrity checks.

Review before installing. Prefer a pinned repository commit, pinned container image digests, and an exact @clawrag/mcp-server version; inspect the Docker Compose file, Dockerfiles, mounts, ports, and environment handling; run it with limited privileges and avoid exposing unrelated API keys or private files to the containers or MCP process.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:20
Finding

Unpinned Remote Docker Deployment Allows Mutable Code Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 20–23
Vulnerability Type: Remote payload retrieval and execution through an unpinned Git repository and Docker deployment
Risk Level: High

bash
git clone https://github.com/2dogsandanerd/ClawRag.git
cd ClawRag
cp .env.example .env
docker compose up -d

Technical Analysis

The installation procedure clones the current state of a remote repository without specifying a reviewed commit hash or immutable release tag. It then immediately processes the repository's Docker Compose configuration and starts its containers.

The effective executable payload is not present in the audited skill package and can change after the skill has been reviewed. Docker Compose files may define arbitrary images, build instructions, entry points, host directory mounts, environment variables, network exposure, Linux capabilities, or privileged container settings. The skill provides no image-digest verification, repository integrity check, or mandatory review step before execution.

Attack Path

  1. An attacker compromises the upstream GitHub repository, a maintainer account, or an indirectly referenced container image.
  2. The attacker modifies the default branch, Compose configuration, Docker build context, or mutable image tag.
  3. A user follows the documented git clone instructions and receives the attacker-controlled version.
  4. The user runs docker compose up -d.
  5. Docker builds or retrieves the modified components and executes them.
  6. Depending on the Compose permissions and mounts, the payload may access configured API keys, application data, host-mounted files, exposed services, and Docker-accessible resources.

Impact Assessment

Successful exploitation can result in arbitrary containerized code execution. The practical scope depends on the Docker daemon configuration and the remote Compose file. If sensitive host paths, the Docker socket, elevated capabilities, host networking, or privi ...[truncated 238 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin the repository to a reviewed commit hash rather than implicitly using the default branch.
  • Reference container images by immutable digest, such as image@sha256:..., instead of mutable tags.
  • Publish expected commit identifiers and image digests in the installation instructions.
  • Require users to inspect the Compose file, Dockerfiles, entry points, mounts, capabilities, ports, and environment-variable handling before startup.
  • Avoid privileged containers, host PID or network modes, sensitive host mounts, and Docker socket exposure.
  • Run containers as non-root users with read-only filesystems, dropped Linux capabilities, resource limits, and narrowly scoped networks where possible.
  • Add signature or checksum verification for downloaded artifacts and container images.
  • Recommend deploying the service in an isolated virtual machine or restricted Docker environment when processing sensitive documents.

T08 · Insecure Dependencies

Error
Location
SKILL.md:31
Finding

Unpinned npm Package Is Downloaded and Executed Through npx

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 31
Vulnerability Type: Unsafe execution of an unpinned third-party dependency
Risk Level: High

bash
openclaw mcp add --transport stdio clawrag npx -y @clawrag/mcp-server

Technical Analysis

The command registers npx -y @clawrag/mcp-server as an MCP server. No exact package version is specified, so npm resolves the package version available under the applicable registry rules at execution time. The -y option suppresses the normal installation confirmation.

Although the changelog references MCP server version v1.1.0, the executable command does not pin that version and does not verify package integrity. Consequently, the code executed by OpenClaw can differ from the code that existed when the skill was reviewed. npm packages may execute code during installation and whenever their command-line entry point is launched.

Attack Path

  1. An attacker compromises the npm publisher account, package registry path, or upstream release process.
  2. The attacker publishes a malicious version of @clawrag/mcp-server.
  3. A user runs the documented registration command or OpenClaw subsequently launches the configured MCP command.
  4. npx resolves and downloads the malicious package without an interactive confirmation.
  5. Package installation hooks or the MCP server entry point execute with the OpenClaw user's operating-system privileges.
  6. The malicious server can access files and environment variables available to that user and inspect or manipulate MCP traffic delivered to the server.

Impact Assessment

Successful exploitation may provide arbitrary code execution with the privileges of the user running OpenClaw. The package could read accessible files and environment variables, steal API credentials, alter MCP responses, tamper with RAG queries, or disclose documents and prompts sent through the MCP connection. The scope is limited by the operating-system permissions and sandbo ...[truncated 101 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin the package to an exact reviewed version, for example @clawrag/mcp-server@1.1.0, rather than relying on the current registry resolution.
  • Use a lockfile and npm integrity metadata to ensure reproducible dependency resolution.
  • Install and inspect the package separately before registering it as an MCP server instead of using automatic npx -y execution.
  • Disable or carefully review package lifecycle scripts during installation where operationally possible.
  • Verify package provenance, publisher identity, signatures, and published checksums.
  • Run the MCP server under a dedicated low-privilege account or sandbox with access only to required files, environment variables, and network destinations.
  • Avoid exposing unrelated API keys or sensitive environment variables to the MCP process.
  • Establish an explicit dependency-update review process before changing the pinned version.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 21)May include surrounding context.

bash
git clone https://github.com/2dogsandanerd/ClawRag.git
cd ClawRag
cp .env.example .env
docker compose up -d

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The skill instructs users to execute an unpinned npm package via npx, which fetches and runs the latest published code at execution time. If the package is compromised, typo-squatted, or updated maliciously, users could execute attacker-controlled code on their machine during setup.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The document is primarily in English, but switches to German in section headings like 'Metadata für ClawHub-Upload' and 'Changelog für Version 1.2.0'. This imposes a locale change without offering a language choice or explaining that the content is intended for a German-specific audience.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.