Back to skill

Security audit

Rapport Memories

Security checks for vulnerabilities and agentic risk

Overview

This memory-search skill is purpose-aligned, but it handles sensitive agent memories with broad indexing, weak privacy controls, and an environment-configurable HTTP embedding endpoint.

Review this before installing. Use only a trusted, preferably local Ollama endpoint; do not point OLLAMA_HOST at an untrusted or remote HTTP service for sensitive memories. Pin or locally build the container and dependencies, limit the mounted workspace, avoid cross-agent memory directories unless intended, and assume the sanitizer may not remove all secrets or personal data.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/memory_rag.py:53
Finding

Agent Memory and Search Queries Can Be Sent to an Arbitrary Plaintext HTTP Endpoint

Content
View full analysis
List[float]: """Generates embedding vector from Ollama API.""" url = f"{self.ollama_host.rstrip('/')}/api/embeddings" data = json.dumps({"model": self.embedding_model, "prompt": text}).encode('utf-8') req = urllib.request.Request( url, data=data, headers={'Content-Type': 'application/json'} ) try: with urllib.request.urlopen(req, timeout=30) as response: res_data = json.loads(response.read().decode('utf-8')) embedding = res_data.get("embedding") if not embedding: raise ValueError("Empty embedding returned by Ollama server") return embedding except Exception as e: raise RuntimeError(f"Failed to fetch embeddings from Ollama model '{self.embedding_model}': {e}") ``` The method is called with indexed memory chunks and search queries: ```python embedding = self._get_embedding(chunk) ``` ```python query_emb = self._get_embedding(query) ``` ### Technical Analysis The embedding server URL is taken directly from the `OLLAMA_HOST` environment variable. The implementation does not validate the destination host, restrict requests to loopback interfaces, enforce HTTPS for remote destinations, or require explicit authorization before transmitting content. During indexing, the text sent to this endpoint originates from persistent agent memory files. During semantic search, the user's query is also sent. Both data types can contain private conversations, personal information, operational context, or credentials that the limited sanitizer ...[truncated 1254 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/memory_rag.py:138
Finding

Incomplete Sanitization Can Persist and Transmit Secrets or Personal Data

Content
View full analysis
str: """Removes code blocks, JSON data, and system diagnostics to index clean content.""" # Remove Markdown code blocks (```code```) text = re.sub(r'```[\s\S]*?```', '', text) lines = [] for line in text.splitlines(): stripped = line.strip() # Skip pure JSON lines if (stripped.startswith('{') and stripped.endswith('}')) or (stripped.startswith('[') and stripped.endswith(']')): try: json.loads(stripped) continue except ValueError: pass # Skip lines containing secret credentials or environment variable defs if re.search(r'(api_key|token|password|credential|secret|auth|private_key)\s*[:=]', stripped, re.IGNORECASE): continue # Skip sandbox shell outputs or commands if stripped.startswith("Task id") or stripped.startswith("Task logs are available at"): continue lines.append(line) cleaned = "\n".join(lines) cleaned = re.sub(r'\n\s*\n', '\n\n', cleaned) # Normalize empty lines return cleaned.strip() ``` ### Technical Analysis The sanitizer removes fenced code blocks, standalone JSON lines, two diagnostic prefixes, and lines containing a small list of security-related words immediately followed by `:` or `=`. This does not provide the privacy guarantees stated in `SKILL.md`. Examples of sensitive content that can survive include: - Bearer tokens written as `Authorization Bearer ...` - Secrets described in prose - Session cookies and connection strings - PEM or other multiline private keys outside fenced blocks - Cloud-provider credentials using unrecognized variable names - Internal paths, ...[truncated 1397 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/memory_rag.py:252
Finding

Workspace-Wide Enumeration Aggregates Memory from All Agent Directories Without an Authorization Boundary

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Mutable Container Image and Unpinned Python Dependencies Create Supply-Chain Risk

Content
View full analysis
=0.4.0 pydantic-settings>=2.0.0 ``` `README.md`: ```bash docker pull carlosdelfino/rapport-openclaw-sandbox:latest ``` ```bash docker build -t carlosdelfino/rapport-openclaw-sandbox:latest . ``` `Dockerfile`: ```dockerfile COPY requirements.txt /tmp/requirements.txt RUN pip install --no-cache-dir -r /tmp/requirements.txt ``` The container also does not declare a non-root runtime user. ### Technical Analysis The Python requirements use open-ended lower bounds rather than exact, hash-verified versions. Consequently, separate builds can install substantially different dependency trees from the one reviewed. The installation instructions recommend a mutable `latest` image from a third-party Docker Hub namespace without pinning an immutable digest or providing provenance verification. Pulling that image executes whatever content the tag references at the time of use, rather than necessarily executing the audited Dockerfile. This is not evidence that the named dependencies or image are currently malicious. The vulnerability is the absence of controls that ensure users execute the reviewed components. ### Attack Path 1. A dependency release, transitive dependency, registry account, or mutable image tag is compromised or replaced. 2. A user follows the documented installation procedure or rebuilds without a lockfile. 3. The container or package manager downloads code different from the audited version. 4. The downloaded code runs during installation, import, or Skill execution. 5. Because `/workspace` is mounted into the container, malicious dependency or image code can access agent memory and other readable workspace files. 6. Running as r ...[truncated 590 chars]
Remediation
View remediation
`. 2. Publish image provenance, a software bill of materials, and reproducible build instructions. 3. Pin direct and transitive Python dependencies to reviewed versions using a lockfile. 4. Require package hashes during installation, such as with `pip --require-hashes`. 5. Run automated vulnerability and provenance scanning for container layers and Python packages. 6. Separate build and runtime stages so compilers, Git, Curl, and development headers are absent from the runtime image. 7. Create and use a dedicated non-root runtime user. 8. Mount the workspace with the minimum required permissions and avoid exposing Docker sockets, host credentials, or unrelated directories. 9. Replace the mutable `latest` recommendation with a versioned, digest-pinned image reference. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (26)

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The README instructs users to pull and run a container image using the mutable latest tag rather than a pinned digest. This creates a supply-chain risk because the image contents can change over time, allowing accidental drift or malicious replacement to affect anyone following the instructions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README describes indexing persistent memory files and using Ollama for embeddings, with OLLAMA_HOST defaulting to http://host.docker.internal:11434, but it does not clearly warn that memory contents may be transmitted out of process to a separate embedding service. Because the skill handles agent memories that may contain sensitive operational context, users may unknowingly expose confidential data to another service or host boundary.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The skill advertises capabilities that imply access to environment variables, file reads/writes, and possible networked embedding/model operations, but it declares no explicit tool scope or permission boundaries. For a memory-oriented skill that indexes transcripts and persistent memory, this omission is dangerous because it can enable overbroad access to sensitive local data and secrets without clear operator review or least-privilege constraints.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill states that it indexes memory files and sanitized session transcripts for semantic recall, but it does not clearly warn users that past conversation content may be retained, embedded, and reused to personalize future responses. This creates a privacy and consent risk: users may disclose sensitive information without realizing it could persist in a searchable long-term memory layer, and sanitization claims in the document are not a substitute for explicit notice and consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code sends memory chunk contents and search queries to the Ollama embeddings endpoint via HTTP, which can disclose sensitive workspace data to another service without explicit user notice or consent. Because the host is environment-configurable, this can also route data to a non-local endpoint, increasing exfiltration risk beyond the stated semantic-memory purpose.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill description emphasizes semantic search, but this code also creates and modifies workspace memory files through add_memory_entry(). That expands the capability from passive retrieval to persistent write access, which can alter agent state, create misleading memory records, or persist sensitive content without clear separation of trust boundaries.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

get_recent_context() concatenates previously stored memory chunks into a prompt-ready block with minimal filtering, which can resurface sensitive or private content wholesale in later interactions. In an agent setting, this creates a data-minimization and cross-context leakage risk, especially when memory contents come from mixed-trust sources or prior conversations.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

Low
Category
Tool Misuse
Confidence
15% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · Dockerfile (reported line 10)May include surrounding context.

dockerfile
sqlite3 \
    git \
    curl \
    && rm -rf /var/lib/apt/lists/*

# Set default working directory (OpenClaw mount point)
WORKDIR /workspace

Tool Parameter Abuse

Low
Category
Tool Misuse
Confidence
15% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · Dockerfile (reported line 10)May include surrounding context.

dockerfile
sqlite3 \
    git \
    curl \
    && rm -rf /var/lib/apt/lists/*

# Set default working directory (OpenClaw mount point)
WORKDIR /workspace

Chaining Abuse

Low
Category
Tool Misuse
Confidence
15% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · Dockerfile (reported line 10)May include surrounding context.

dockerfile
sqlite3 \
    git \
    curl \
    && rm -rf /var/lib/apt/lists/*

# Set default working directory (OpenClaw mount point)
WORKDIR /workspace

Tool Parameter Abuse

Low
Category
Tool Misuse
Confidence
15% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · README.md (reported line 65)May include surrounding context.

Initialize Database

bash
docker run --rm -v $(pwd):/workspace carlosdelfino/rapport-openclaw-sandbox:latest /skills/rapport-memories/scripts/memory_rag.py init

Index Workspace Memories

Tool Parameter Abuse

Low
Category
Tool Misuse
Confidence
15% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · README.md (reported line 71)May include surrounding context.

Initialize Database

bash
docker run --rm -v $(pwd):/workspace carlosdelfino/rapport-openclaw-sandbox:latest /skills/rapport-memories/scripts/memory_rag.py init

Index Workspace Memories

Tool Parameter Abuse

Low
Category
Tool Misuse
Confidence
15% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · README.md (reported line 77)May include surrounding context.

Initialize Database

bash
docker run --rm -v $(pwd):/workspace carlosdelfino/rapport-openclaw-sandbox:latest /skills/rapport-memories/scripts/memory_rag.py init

Index Workspace Memories

Tool Parameter Abuse

Low
Category
Tool Misuse
Confidence
15% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · README.md (reported line 87)May include surrounding context.

Initialize Database

bash
docker run --rm -v $(pwd):/workspace carlosdelfino/rapport-openclaw-sandbox:latest /skills/rapport-memories/scripts/memory_rag.py init

Index Workspace Memories

Tool Parameter Abuse

Low
Category
Tool Misuse
Confidence
15% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · README.md (reported line 94)May include surrounding context.

Initialize Database

bash
docker run --rm -v $(pwd):/workspace carlosdelfino/rapport-openclaw-sandbox:latest /skills/rapport-memories/scripts/memory_rag.py init

Index Workspace Memories

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency specifier chromadb>=0.4.0 is unpinned, which allows builds to resolve to different versions over time, including newly introduced vulnerable or incompatible releases. In a memory/RAG skill that depends on a network-facing data component, this weakens supply-chain integrity and makes it harder to verify whether deployed versions include fixes for known ChromaDB vulnerabilities.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
chromadb>=0.4.0
pydantic-settings>=2.0.0

Unverifiable Dependency: chromadb has 8 known advisory(ies) (CVE-2026-45830 (ChromaDB allows any authenticated users to arbitrarily read, write, update, or d); CVE-2026-45833 (ChromaDB has a code injection vulnerability); CVE-2026-45829 (ChromaDB Python project has a pre-authentication code injection vulnerability) +5 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
92% confidence
Finding

chromadb has multiple known advisories, including code injection and unauthorized access issues, and the manifest does not pin a version, so there is no assurance the installed release is patched. Given this skill's semantic memory/RAG context, ChromaDB is likely central to storing and retrieving contextual data, which increases the consequence of compromise through data exposure, tampering, or code execution paths in the dependency.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
91% confidence
Finding

The dependency pydantic-settings>=2.0.0 is also unpinned, so installations may drift to different versions across environments and time. This creates supply-chain uncertainty and may inadvertently pull in versions affected by security issues or behavioral changes, especially relevant where settings may influence secret handling and runtime configuration.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
chromadb>=0.4.0
pydantic-settings>=2.0.0

Unverifiable Dependency: pydantic-settings has 1 known advisory(ies) (CVE-2026-58203 (pydantic-settings: NestedSecretsSettingsSource follows symlinks outside secrets_)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
84% confidence
Finding

pydantic-settings has a known advisory related to NestedSecretsSettingsSource following symlinks outside the intended secrets directory, and because the requirement is unpinned, affected versions may be installed unknowingly. In an agent skill, configuration and secret loading are sensitive operations, so a vulnerable version could enable unintended secret disclosure if an attacker can influence filesystem layout or secret sources.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The skill reads environment variables such as OLLAMA_HOST and model-selection settings, which influence outbound requests to an embedding service. While embeddings are relevant to RAG, relying on environment-driven external endpoint selection introduces configuration and connectivity capability beyond the manifest's plain description of semantic memory extension.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.