T08 · Insecure Dependencies
- Location
handler.py:14- Finding
Execution of Unpackaged Code from a Mutable External Import Path
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This RAG search skill matches its stated purpose, but it depends on mutable unpackaged Python code from a hard-coded root workspace path and does not clearly disclose external embedding/rerank data handling.
Review this before installing. Use it only in a controlled environment where /root/.openclaw/workspace/rag_system/scripts is trusted, reviewed, and read-only, and where users understand that queries may be processed by embedding/rerank components. The schema should be fixed and top_k should be bounded before broad deployment.
handler.py:14Execution of Unpackaged Code from a Mutable External Import Path
schema.json:8Malformed Schema and Missing Bounds Validation for top_k
The usage example at L14 instructs invocation exclusively in Chinese, which can impose a language constraint on users without opt-in. The file does not state that the skill is region-specific or provide an alternative language option, so this appears to violate the language/locale policy criterion.
The module documentation says 'Minimal RAG retrieval tool' and explicitly states '不总结、不改写、不推理,只返回原文检索结果' (no summarization, rewriting, or reasoning; only return original retrieval results). However, the implementation computes embeddings and then calls a reranking client to reorder results before returning them, which means the output is not merely raw retrieval output. This is an active contradiction in intent documentation, not just an omitted implementation detail.
The skill sends the user's query to external embedding and rerank clients without any disclosure, consent flow, or indication of data handling. If users submit sensitive internal, legal, or personal data, that content may be exposed to third-party services or logged outside the local environment, creating a confidentiality and compliance risk.
The manifest mixes English top-level metadata with Chinese tag and field descriptions such as the input/output descriptions, indicating the skill is intended to operate in Chinese. There is no statement that the skill is region-specific or that users may choose their preferred language, which can violate language/locale policy requirements.
Natural-language instructions and usage text in this file are presented exclusively in Chinese, including the module description and command-line help. That can constitute a language policy issue when the skill does not offer an alternative language or indicate that the locale restriction is intentional and justified.
This JSON schema contains user-facing natural-language descriptions exclusively in Chinese, such as the field descriptions at L06, L10, and throughout the result schema. Because the file does not indicate that the skill is intentionally region-specific or provide an opt-in language choice, it may violate language/locale policy expectations.
No suspicious patterns detected.