Back to skill

Security audit

RAG Search

Security checks for vulnerabilities and agentic risk

Overview

This RAG search skill matches its stated purpose, but it depends on mutable unpackaged Python code from a hard-coded root workspace path and does not clearly disclose external embedding/rerank data handling.

Review this before installing. Use it only in a controlled environment where /root/.openclaw/workspace/rag_system/scripts is trusted, reviewed, and read-only, and where users understand that queries may be processed by embedding/rerank components. The schema should be fixed and top_k should be bounded before broad deployment.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
handler.py:14
Finding

Execution of Unpackaged Code from a Mutable External Import Path

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
schema.json:8
Finding

Malformed Schema and Missing Bounds Validation for top_k

Content
View full analysis
2 else 5 ``` ### Technical Analysis The schema is not valid JSON because the `results.description` value lacks an opening quotation mark. A standards-compliant JSON parser will reject the schema, potentially preventing the platform from applying any declared input validation. In addition, `top_k` is declared as a generic JSON `number` without minimum or maximum constraints. The implementation treats it as an integer and forwards it to external retrieval and reranking components. Fractional values can fail when used as a slice bound or when passed to dependencies, while zero or negative values may produce inconsistent behavior. Although vector recall is capped at 20 through `min(top_k * 4, 20)`, `top_k` itself is passed directly as `top_n` to the external reranker. The command-line interface converts the value to an integer but does not enforce positive bounds. The callable `run()` function performs no type or range validation at all. Errors are caught and returned through `str(e)`, which may disclose implementation or dependency details to callers. ### Attack Path 1. A caller invokes `run()` directly with a fractional, negative, excessively large, or otherwise unsupported `top_k` value. 2. Because the schema is malformed, schema loading may fail and platform-level validation may not be applie ...[truncated 768 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The usage example at L14 instructs invocation exclusively in Chinese, which can impose a language constraint on users without opt-in. The file does not state that the skill is region-specific or provide an alternative language option, so this appears to violate the language/locale policy criterion.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The module documentation says 'Minimal RAG retrieval tool' and explicitly states '不总结、不改写、不推理,只返回原文检索结果' (no summarization, rewriting, or reasoning; only return original retrieval results). However, the implementation computes embeddings and then calls a reranking client to reorder results before returning them, which means the output is not merely raw retrieval output. This is an active contradiction in intent documentation, not just an omitted implementation detail.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill sends the user's query to external embedding and rerank clients without any disclosure, consent flow, or indication of data handling. If users submit sensitive internal, legal, or personal data, that content may be exposed to third-party services or logged outside the local environment, creating a confidentiality and compliance risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest mixes English top-level metadata with Chinese tag and field descriptions such as the input/output descriptions, indicating the skill is intended to operate in Chinese. There is no statement that the skill is region-specific or that users may choose their preferred language, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

Natural-language instructions and usage text in this file are presented exclusively in Chinese, including the module description and command-line help. That can constitute a language policy issue when the skill does not offer an alternative language or indicate that the locale restriction is intentional and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This JSON schema contains user-facing natural-language descriptions exclusively in Chinese, such as the field descriptions at L06, L10, and throughout the result schema. Because the file does not indicate that the skill is intentionally region-specific or provide an opt-in language choice, it may violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.