Back to skill

Security audit

Chromadb Plugin

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real ChromaDB memory plugin, but it needs review because remote mode can expose memory data and API keys and the query API contains a hidden special-case response.

Review the code before installing. Use a virtual environment and pinned dependencies, back up existing vector-store data before migration, avoid running deletion examples on production data, and only use remote ChromaDB over HTTPS with protected, narrowly scoped API keys. Be aware that one special query string returns a nonstandard response.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Warning
Location
install.sh:19
Finding

Unpinned Third-Party Dependencies Permit Supply-Chain Code Execution

Content
View full analysis

Vulnerability Details

File Location: install.sh:19-24; README.md:24-27; docs/quick_start_en.md:18-21; docs/zh-CN/ChromaDB插件_快速安装指南.md:30-33
Vulnerability Type: Unrestricted dependency installation
Risk Level: Medium

Vulnerable Code

install.sh:19-24:

bash
echo "[*] Installing dependencies..."
pip3 install chromadb sentence-transformers pyyaml
if [ $? -ne 0 ]; then
    echo "[!] Dependency installation failed"
    exit 1
fi

README.md:24-27:

bash
### Manual install
```bash
pip install chromadb openclaw-extension-chromadb
text

`docs/quick_start_en.md:18-21`:

```bash
### Manual install
```bash
pip install chromadb sentence-transformers openclaw-extension-chromadb
text

### Technical Analysis

The installer retrieves and installs the latest available versions of `chromadb`, `sentence-transformers`, and `pyyaml` without a lock file, version constraints, or integrity hashes. Python package installation can execute package-controlled build and installation code with the privileges of the invoking user.

The manual installation documentation additionally instructs users to install `openclaw-extension-chromadb`. That package is not part of the audited project and is not listed among the dependencies in `SKILL.md`. Its necessity, version, provenance, and integrity are therefore not established by the audited source.

This does not prove that any named package is currently malicious. It creates a supply-chain exposure in which the code executed during future installations can differ from the code that was reviewed.

### Attack Path

1. An attacker compromises a dependency release, its maintainer account, or the package-index delivery path, or publishes a malicious package under the additional documented package name.
2. A user executes `install.sh` or follows one of the manual `pip install` instructions.
3. `pip` resolves the dependency to the attacker-
...[truncated 775 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin every direct and transitive dependency to a reviewed version using a lock file.
  2. Require package hashes, for example through pip install --require-hashes -r requirements.txt.
  3. Install dependencies inside a dedicated virtual environment rather than the user's global Python environment.
  4. Use a trusted, explicitly configured package index and retain reviewed package artifacts where practical.
  5. Remove openclaw-extension-chromadb from the documentation unless it is necessary and its ownership, package source, exact version, and integrity are verified.
  6. Make the installer invoke the selected interpreter consistently, such as python3 -m pip, to avoid installing into an unintended environment.
  7. Add dependency scanning and lock-file update review to the release process.

T09 · Insecure Skill Coding Practices

Error
Location
docs/zh-CN/ChromaDB插件_配置说明.md:86
Finding

Production Configuration Permits Bearer Credentials and Memory Data over Plaintext HTTP

Content
View full analysis

Vulnerability Details

File Location: docs/zh-CN/ChromaDB插件_配置说明.md:86-88; chromadb_plugin.py:24-30
Vulnerability Type: Missing enforcement of transport encryption
Risk Level: High

Vulnerable Code

docs/zh-CN/ChromaDB插件_配置说明.md:86-88:

yaml
host: "http://192.168.1.100"
port: 8000
api_key: "your-production-api-key"

chromadb_plugin.py:24-30:

python
if host and port:
    # Cloud mode
    self.client = chromadb.HttpClient(
        host=host,
        port=port,
        headers={"Authorization": f"Bearer {api_key}"} if api_key else None
    )

Technical Analysis

The production configuration example explicitly combines an API key with an http:// endpoint. The implementation places that key in an Authorization: Bearer request header but does not reject plaintext HTTP, require TLS, or expose documented certificate-verification controls.

When an HTTP transport is used, the authorization header, uploaded documents, metadata, query text, and returned memory records may be visible to network intermediaries. Plaintext traffic also lacks server authentication and integrity protection, allowing an active attacker to impersonate the ChromaDB service or modify responses.

Storing the API key directly in YAML can additionally expose it to users, backup systems, or processes that can read the configuration file.

Attack Path

  1. An administrator adopts the documented production example and configures a remote ChromaDB endpoint using http:// with an API key.
  2. The plugin constructs the bearer authorization header and communicates with the remote service without TLS.
  3. An attacker with access to the same network, a compromised router, or another suitable interception point observes or alters the connection.
  4. The attacker captures the bearer key and sensitive memory traffic or impersonates the remote database.
  5. The stolen key is replayed against the ChromaDB ser ...[truncated 652 chars]
Remediation
View remediation

Remediation Suggestions

  1. Require HTTPS for every remote ChromaDB connection, especially when an API key is configured.
  2. Validate the configured host during initialization and reject http:// unless an explicit, prominently warned development-only override is enabled.
  3. Replace the production documentation example with an https:// endpoint.
  4. Ensure certificate and hostname verification remain enabled; provide a secure mechanism for private certificate authorities rather than disabling verification.
  5. Load API keys from protected environment variables or a secret manager instead of recommending plaintext configuration values.
  6. Restrict configuration-file permissions to the service account.
  7. Use narrowly scoped, revocable API credentials and document key rotation procedures.
  8. Consider mutual TLS or equivalent service authentication for sensitive deployments.

other

Note
Location
chromadb_plugin.py:64
Finding

Undocumented Magic Query Bypasses Vector Retrieval and Changes the Response Schema

Content
View full analysis

Vulnerability Details

File Location: chromadb_plugin.py:64-73
Vulnerability Type: Hidden query-triggered response manipulation
Risk Level: Low

Vulnerable Code

python
# 【隐性水印标记:原创校验彩蛋,抄袭者不会注意到此处逻辑】
if len(query_texts) > 0 and query_texts[0] == "LANLAN_ORIGIN_CHECK":
    return {
        "original": True,
        "author": "LanLan AI Lab",
        "first_release": "2026-03-28",
        "source": "https://clawhub.ai/lulan3954-a11y/chromadb-plugin",
        "mark": "LANLAN-20260328-ORIGINAL-7A9F3C"
    }

Technical Analysis

The query method contains a hidden sentinel value that bypasses the normal ChromaDB query operation. When the first query equals LANLAN_ORIGIN_CHECK, the method returns attribution data instead of the documented result structure containing ids, documents, metadatas, and distances.

This behavior is not part of the documented API contract. Downstream code reasonably expects every successful query to use the standard ChromaDB response schema. A user or external input source capable of controlling the query can therefore trigger an unexpected response and potentially cause exceptions or unrelated content to enter a retrieval workflow.

This branch does not directly execute code or access additional privileges, but it is concealed behavior that undermines response integrity and interface reliability.

Attack Path

  1. An application passes user-controlled text to ChromaDBStore.query.
  2. An attacker submits LANLAN_ORIGIN_CHECK as the first query string.
  3. The plugin bypasses vector retrieval and returns the special attribution dictionary.
  4. Downstream code attempts to access expected fields such as results["documents"] or incorporates the unexpected values into an Agent context.
  5. The workflow may fail with a key error, produce an invalid response, or expose unrelated attribution content.

Impact Assessment

The principal impact is avai ...[truncated 485 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the magic-query branch from the normal query method.
  2. If provenance information is required, expose it through a separately named and documented method such as get_provenance().
  3. Ensure every successful query call returns one stable, documented schema.
  4. Add tests that submit the sentinel and other unusual input values to confirm they are processed as ordinary search text.
  5. Validate response structures at integration boundaries so malformed or unexpected plugin responses fail safely without affecting broader Agent execution.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (21)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The migration instructions tell users to run an import script against existing LanceDB and ChromaDB paths without warning that destination data may be changed, duplicated, or overwritten. In a memory/vector-store skill, this can lead to silent corruption, duplicate embeddings, or loss of existing collections if users assume the operation is non-destructive.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The plugin claims full LanceDB compatibility while embedding hidden, non-vector-store behavior that returns watermark metadata for a magic query string. This violates interface expectations and creates a covert alternate code path that can leak implementation metadata or break callers that trust the documented response schema.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

In cloud mode, the plugin creates an HTTP client and later sends query and document data through that client, but this file provides no confirmation prompt, logging, or warning comment/docstring that user content may be transmitted off-host. Because this is a code file handling network operations and potentially user-supplied texts, a visible disclosure is expected.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The query method can return a completely different object when given the sentinel string LANLAN_ORIGIN_CHECK, despite being documented as a standard vector-store query interface. This hidden trigger can cause downstream logic failures, unexpected information disclosure, and trust-boundary violations in systems that treat plugin output as structured search results.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The delete method performs a destructive operation on stored documents, but the implementation includes no confirmation prompt, warning log, or cautionary documentation beyond a brief interface description. For a code file, destructive operations should have some explicit disclosure unless clearly covered elsewhere.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The natural-language comment states that the default is a Chinese model, and the configured model value reinforces that locale-specific choice. Because this file is a manifest/config file, SQP-3 applies, and there is no indication of user opt-in or a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation presents destructive operations such as deleting records, clearing all data, and deleting collections without any warning, safeguards, or confirmation guidance. In an API usage guide, this can lead users to run irreversible commands in production or against the wrong collection, causing avoidable data loss and integrity issues.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The guide includes collection deletion and JSON import/export examples without explaining overwrite risks, data leakage concerns, or the effects of writing to local files. This omission increases the chance of accidental data loss, unsafe file handling, or exporting sensitive vector data and metadata to insecure locations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manual migration example exports the full database contents, including documents, metadata, and IDs, into a plaintext JSON file without any warning about sensitive data handling, access controls, encryption, or secure deletion. In a knowledge-base or vector-store context, those fields may contain proprietary content, personal data, tokens, or other sensitive material, so creating an unprotected bulk export increases the risk of local disclosure, accidental commits, backups, or misuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

该 markdown 文件说明自动安装脚本会“自动配置向量库存储路径”“生成默认配置文件”,后文还包含迁移脚本与删除测试成功等会影响本地数据和配置的行为,但正文未在对应步骤附近明确警示这些操作将修改用户环境、文件或数据。虽然 L78-L79 提到建议测试和备份,但属于较后置的通用注意事项,未充分披露一键安装、迁移和测试过程中的具体影响。

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · install.sh (reported line 27)May include surrounding context.

sh
fi

echo "[*] Copying plugin files..."
mkdir -p ~/.openclaw/extensions/chromadb
cp chromadb_plugin.py ~/.openclaw/extensions/chromadb/
cp README.md ~/.openclaw/extensions/chromadb/
cp -r docs ~/.openclaw/extensions/chromadb/

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This shell script creates directories under ~/.openclaw, copies plugin files, and overwrites or creates a default configuration file. Although it prints progress messages, it does not clearly warn the user that it will modify files in their home directory or prompt before doing so.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The docstring promises "100% data consistency guaranteed" and "rollback supported," but the implementation only performs a post-migration count check and has no transactional rollback or recovery logic. This can mislead operators into trusting the tool for destructive or production migrations, increasing the chance of silent corruption, duplication, partial migration, or failed recovery after an error.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The natural-language header contains Chinese-only notices and watermark text without offering any language choice or documenting a justified region-specific constraint. This can violate language/locale policy when a skill file embeds user-facing or organizational instructions in a forced language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The entire skill file is written only in Chinese and does not offer an alternative language, user opt-in, or any justification for a Chinese-only locale constraint. Under the policy, language or locale restrictions should either be optional for the user or clearly documented as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

Line L03 presents a prominent legal/originality notice only in Chinese, while the surrounding README is primarily in English. This can create a language accessibility policy issue because users are forced to rely on a specific language for important usage and legal context without opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file name and content present the guide specifically as an English-only variant (quick_start_en.md) without any indication that users may choose another language or that English is required for a justified regional or compliance reason. This can violate a language/locale policy when a skill implicitly forces a specific language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

该文件位于 docs/zh-CN/ 且全文以简体中文提供说明,体现了特定语言/地区版本的内容约束,但文中未说明是否提供其他语言版本或允许用户选择语言。按规则,强制特定语言而无用户 opt-in 或合理限定说明,可构成自然语言层面的语言/locale 政策问题。

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

这是一个 markdown 文件,适用 SQP-2。文档明确指导使用 CHROMADB_API_KEY 配置凭据,但没有任何用户告警说明该值属于敏感信息、应通过安全密钥管理或环境注入方式提供,避免写入公开配置或输出到日志。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The file includes natural-language notices only in Chinese, which can violate a language/locale policy when no user opt-in or region-specific justification is present. This is a natural-language policy concern because the script otherwise targets general Linux/macOS users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The header contains Chinese-language notices and statements, which constitutes a natural-language locale choice embedded in the skill file. Under the policy, forcing a specific language without user opt-in can be a locale-policy violation, and this file provides no indication of user choice or region-specific justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.