Back to skill

Security audit

ClawRAG - Self-hosted RAG & Memory

Security checks across malware telemetry and agentic risk

Overview

ClawRAG is a disclosed self-hosted RAG/MCP setup whose Docker and npm install steps fit its purpose, but users should trust the upstream project before running it.

Install only if you trust the ClawRAG GitHub repository, npm package, and Docker images. Review the compose file and .env before running, choose a narrow DOCS_DIR containing only documents you intend to index, and avoid configuring cloud API keys unless you are comfortable sending document-derived content to that provider.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.