Security audit
ClawRAG - Self-hosted RAG & Memory
Security checks across malware telemetry and agentic risk
Overview
ClawRAG is a disclosed self-hosted RAG/MCP setup whose Docker and npm install steps fit its purpose, but users should trust the upstream project before running it.
Install only if you trust the ClawRAG GitHub repository, npm package, and Docker images. Review the compose file and .env before running, choose a narrow DOCS_DIR containing only documents you intend to index, and avoid configuring cloud API keys unless you are comfortable sending document-derived content to that provider.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
66/66 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
