Back to skill

Security audit

RAGLite

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent, but users should review it because it encourages processing sensitive documents while defaulting to an insufficiently explained model engine and installing mutable Python packages at setup time.

Install only if you are comfortable with the OpenClaw engine handling the documents you process, or always pass an explicitly understood --engine value. Avoid running it on medical, internal, or confidential documents until the engine’s locality and retention behavior are clear. Prefer installing in an isolated environment and do not set RAGLITE_PIP_INDEX_URL unless you fully trust that package index.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
scripts/install.sh:14
Finding

Unpinned Dependencies and Untrusted Configurable Package Index

Content
View full analysis

Vulnerability Details

File Location: scripts/install.sh, lines 14–20
Vulnerability Type: Supply-chain exposure through unpinned packages and unsafe package-index configuration
Risk Level: High

bash
python -m pip install --upgrade pip setuptools wheel >/dev/null

if [[ -n "${RAGLITE_PIP_INDEX_URL:-}" ]]; then
  python -m pip install --upgrade -i "$RAGLITE_PIP_INDEX_URL" --extra-index-url https://pypi.org/simple raglite-chromadb
else
  python -m pip install --upgrade raglite-chromadb
fi

Technical Analysis

The installer downloads and installs the latest available versions of pip, setuptools, wheel, and raglite-chromadb without exact version constraints or cryptographic hashes. Consequently, the code executed during installation is not fixed to the version reviewed with this skill and may change whenever the installer runs.

The RAGLITE_PIP_INDEX_URL environment variable also permits an arbitrary package repository to become the primary index. Combining a configurable primary index with the public PyPI repository through --extra-index-url exposes package resolution to dependency-confusion and malicious-index attacks. An attacker who can influence the environment, package index, DNS/network path, or an eligible package release may cause pip to select and install attacker-controlled content.

Python packages can execute code during build and installation, and the resulting package is subsequently trusted when raglite is invoked. This creates a code-execution path outside the audited project files.

Attack Path

  1. An attacker compromises an eligible package release, publishes a dependency-confusion candidate, or causes RAGLITE_PIP_INDEX_URL to reference an attacker-controlled package index.
  2. A user runs scripts/install.sh.
  3. Pip resolves unpinned package versions from the configured index and/or PyPI.
  4. Pip downloads the attacker-controlled package or dependency.
  5. Malicious build, installation, or runtime cod ...[truncated 839 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin every direct dependency to a reviewed, exact version, including raglite-chromadb, pip, setuptools, and wheel.
  2. Generate a lock file containing all transitive dependencies and their cryptographic hashes.
  3. Install with --require-hashes so modified or unexpected distributions are rejected.
  4. Avoid combining an arbitrary primary index with PyPI through --extra-index-url. Use a single trusted repository or a controlled mirror containing all approved packages.
  5. If custom indexes are required, validate RAGLITE_PIP_INDEX_URL against an explicit allowlist and require authenticated HTTPS with appropriate certificate verification.
  6. Prefer prebuilt, verified wheels where possible and disable unnecessary source builds to reduce installation-time code execution.
  7. Perform dependency scanning and package provenance verification before updating the lock file.
  8. Reproduce installation in an isolated, least-privileged environment before promoting dependency updates.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly promotes use with highly sensitive local/private knowledge, including medical records and internal runbooks, while also stating that the default condensation engine is OpenClaw unless overridden. If that default engine sends document contents to an external model service, users may unknowingly exfiltrate sensitive documents during distillation, which is a serious privacy and compliance risk.

Content

No source excerpt is available for this finding.

Memory Manipulation

High
Category
Memory Poisoning
Confidence
85% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · SKILL.md (reported line 88)May include surrounding context.

md
2) **Index** locally into Chroma
3) **Query** with hybrid retrieval (vector + keyword)

It doesn’t replace memory/context — it’s the place to store what you need again.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The documentation says the skill defaults to a specific engine unless the user passes --engine explicitly, which removes informed choice at the point where sensitive content may be processed. In the context of a document-distillation workflow, silent defaults can cause users to process private data with an engine they did not knowingly select.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The comment and argument-rewrite logic show that the skill defaults to a specific engine without asking for user opt-in. If engine choice implies language or locale behavior, this is a natural-language policy concern because the script enforces a default rather than presenting a choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.