Back to skill

Security audit

RAGLite

Security checks across malware telemetry and agentic risk

Overview

RAGLite is a coherent local document indexing skill with ordinary privacy and package-installation cautions, but no evidence of hidden, destructive, or exfiltrating behavior.

Install only if you trust the PyPI package source. Index narrow, intentional folders, and avoid secrets or regulated records unless you understand where the output directory and Chroma collection are stored, who can access them, whether document contents are sent to an engine or endpoint, and how to delete the artifacts later.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
83% confidence
Finding
The skill explicitly encourages use with highly sensitive data such as medical records and internal documents, but the security note focuses only on prompt injection and not on data handling risks like retention, local exposure, indexing persistence, model/provider transmission, or misconfigured Chroma endpoints. That omission can cause users to process sensitive material without understanding where it is stored, how long it persists, or whether third-party engines may receive contents.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.