Back to skill

Security audit

Rag Retriever

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent RAG document-search skill, but it needs review because it can persist indexed content and use under-disclosed external embedding/model sources with supply-chain and prompt-injection risks.

Review this before installing in sensitive environments. Avoid indexing secrets, credentials, personal data, or proprietary corpora unless you intend them to be stored locally and possibly embedded. Use the default local/simple path for sensitive data, require explicit approval before enabling OpenAI embeddings, pin and verify model artifacts, avoid the hardcoded mirror or make it opt-in, and update vulnerable transitive dependencies. Treat retrieved document text as untrusted evidence, not instructions for an agent to follow.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Warning
Location
src/transformers-embedding.js:24
Finding

Unverified Model Downloads from a Hardcoded Third-Party Mirror

Content
View full analysis
Remediation
View remediation

other

Error
Location
src/rag2.js:207
Finding

Retrieved Documents Are Inserted Verbatim into Downstream LLM Prompts

Content
View full analysis
{ return `[${i + 1}] ${r.content}`; }); return { context: contextParts.join(separator), hasResults: true, query, resultsCount: results.resultsCount, citations: results.citations, prompt: this.buildAugmentedPrompt(query, contextParts) }; } buildAugmentedPrompt(query, contextParts) { return `Based on the following context, answer the question. Use citations [1], [2], etc. to reference sources. Context: ${contextParts.join('\n\n')} Question: ${query} Answer:`; } ``` The basic retriever also returns raw document content as LLM-ready context: ```js async retrieveForRAG(query, options = {}) { const results = await this.retrieve(query, options); const context = results .map((r, i) => `[${i + 1}] ${r.content}`) .join('\n\n'); ``` ### Technical Analysis Indexed documents are untrusted data, but the implementation concatenates their contents directly into a natural-language prompt. There is no explicit instruction telling the downstream model to treat retrieved text exclusively as evidence, no separation between instructions and data beyond ordinary labels, and no detection of instruction-like content. RAG systems are vulnerable to indirect prompt injection when an attacker places model-directed instructions inside a document. Retrieval then transfers those instructions into the model's context. The model may interpret them as part of the active task rather than as q ...[truncated 1768 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/retriever.js:45
Finding

Invalid Chunking Configuration Can Cause a Non-Terminating Loop

Content
View full analysis
start) { end = separatorIndex + this.separator.length; } } const chunkContent = text.slice(start, end); chunks.push({ id: this.generateId(chunkContent + chunkIndex), content: chunkContent.trim(), metadata: { ...metadata, chunkIndex, charStart: start, charEnd: end } }); start = end - this.overlap; if (start < 0) start = end; chunkIndex++; } ``` The RAG 2.0 chunker contains the same progress assumption: ```js while (start < content.length) { let end = start + chunkSize; if (end < content.length) { const sepIndex = content.lastIndexOf(separator, end); if (sepIndex > start) { end = sepIndex + separator.length; } } chunks.push({ content: content.slice(start, end).trim(), metadata: { ...metadata, chunkIndex, charStart: start, charEnd: end } }); start = end - chunkOverlap; if (start < 0) start = end; chunkIndex++; } ``` ### Technical Analysis Neither `ChunkingStrategy` nor `RAG2Retriever` validates `chunkSize` and overlap values. The loops assume that the next `start` offset is greater than the current offset. If overlap equals chunk size and no earlier separator changes the chunk boundary, then: ```text end = start + chunkSize nextStart = end - overlap nextStart = start ``` The loop therefore never advances. If overlap is greater than chunk size, the next offset can move backward or repeatedly reset, also preventing reliable termination. Each iteration appends another ...[truncated 1165 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (54)

Harmful Content Injection

Critical
Category
Prompt Injection
Confidence
70% confidence
Finding

This content may contain harmful instructions that could cause physical harm if followed. CRITICAL: Review carefully before use.

Content

Scanner excerpt · data/model-cache/tokenizer.json (reported line 29758)May include surrounding context.

json
"disgrace": 29591,
      "infused": 29592,
      "pudding": 29593,
      "stalks": 29594,
      "##urbed": 29595,
      "arsenic": 29596,
      "leases": 29597,
      "##hyl": 29598,
      "##rrard": 29599,
      "collarbone": 29600,
      "##waite": 29601,

Harmful Content Injection

Critical
Category
Prompt Injection
Confidence
70% confidence
Finding

This content may contain harmful instructions that could cause physical harm if followed. CRITICAL: Review carefully before use.

Content

Scanner excerpt · data/models/all-MiniLM-L6-v2/tokenizer.json (reported line 29758)May include surrounding context.

json
"disgrace": 29591,
      "infused": 29592,
      "pudding": 29593,
      "stalks": 29594,
      "##urbed": 29595,
      "arsenic": 29596,
      "leases": 29597,
      "##hyl": 29598,
      "##rrard": 29599,
      "collarbone": 29600,
      "##waite": 29601,

Known Vulnerable Dependency: protobufjs==7.5.4 — 12 advisory(ies): CVE-2026-44294 (protobuf.js: Denial of service from crafted field names in generated code); CVE-2026-44293 (protobuf.js: Code injection through bytes field defaults in generated toObject c); CVE-2026-44289 (protobuf.js: Denial of service through unbounded protobuf recursion) +9 more

Critical
Category
Supply Chain
Confidence
90% confidence
Finding

protobufjs 7.5.4 is reported with multiple serious advisories including denial of service and code-generation-related injection issues. Even though this is transitive through onnxruntime-web, bundling a dependency with numerous critical flaws materially increases attack surface, especially in a retrieval/ML skill that may ingest external model artifacts or serialized data formats.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: tar==7.5.12 — 6 advisory(ies): CVE-2026-59873 (node-tar: Decompression/parse DoS via unlimited input); CVE-2026-59874 (node-tar: Negative tar entry size causes infinite loop in archive replace); CVE-2026-59875 (node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records) +3 more

Critical
Category
Supply Chain
Confidence
90% confidence
Finding

tar 7.5.12 has multiple critical advisories including decompression and parsing denial-of-service conditions. This matters because onnxruntime-node has an install script and depends on tar, so the package introduces risk during installation and possibly runtime archive handling; supply-chain and CI environments are especially exposed if attacker-controlled archives can be processed.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

md
node src/rag-skill.js init my_docs

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 40)May include surrounding context.

md
node src/rag-skill.js init my_docs

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 45)May include surrounding context.

md
node src/rag-skill.js init my_docs

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 50)May include surrounding context.

md
node src/rag-skill.js init my_docs

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 90)May include surrounding context.

md
import { RAGRetriever } from './src/retriever.js';

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 182)May include surrounding context.

md
node test/retriever.test.js

Known Vulnerable Dependency: form-data==4.0.5 — 1 advisory(ies): CVE-2026-12143 (form-data: CRLF injection in form-data via unescaped multipart field names and f)

High
Category
Supply Chain
Confidence
92% confidence
Finding

form-data 4.0.5 is flagged for CRLF injection via multipart field names/values. This can be dangerous if the skill constructs multipart requests from untrusted input, because attacker-controlled fields may smuggle unintended headers or manipulate downstream HTTP request bodies; the presence of the OpenAI client in the dependency tree makes outbound multipart-capable HTTP behavior plausible.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: sharp==0.34.5 — 2 advisory(ies): GHSA-f88m-g3jw-g9cj (sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-); GHSA-rgj7-g3m4-5g8c (sharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545)

High
Category
Supply Chain
Confidence
88% confidence
Finding

sharp 0.34.5 is flagged for inherited native-library vulnerabilities in image parsing libraries such as libvips/libheif. This is particularly relevant in ML/retrieval contexts because image preprocessing is common; if the skill ever accepts attacker-supplied images, native parser flaws can lead to crashes, denial of service, or potentially memory-safety exploitation in the underlying library stack.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The entire skill design document is written in Chinese and does not indicate that users may choose another language or that the language restriction is required for a region-specific purpose. Under the policy, forcing a specific language without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file documents commands and API examples for adding arbitrary documents into a local RAG database, including examples that read files and store their contents for later retrieval. The README does not warn users that ingested content may contain sensitive or private data that will be persisted and surfaced in retrieval results, which is a user-data/privacy relevant behavior for markdown descriptions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The natural-language note says the current system '只支持英文分词' (only supports English tokenization), which imposes a language constraint. The file does not present this as a user-selectable option or clearly justify it as a narrowly scoped region/language-specific tool, so it conflicts with the language/locale policy criteria.

Content

No source excerpt is available for this finding.

YARA rule 'network_reconnaissance': Network reconnaissance and scanning patterns [hacktools]

Medium
Category
YARA Match
Confidence
65% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · data/model-cache/tokenizer.json (reported line 9367)May include surrounding context.

json
nquest": 9187,
      "dubbed": 9188,
      "##tv": 9189,
      "halt": 9190,
      "brave": 9191,
      "brunswick": 9192,
      "doi": 9193,
      "arched": 9194,
      "curtis": 9195,
      "divorced": 9196,
      "predominantly": 9197,
      "somerset": 9198,
      "streams": 9199,
      "ugly": 9200,
      "zoo": 9201,
      "horrible": 9202,
      "curved": 9203,
      "buenos": 9204,
      "fierce": 9205,
      "dictionary": 9206,
      "vector": 9207,
      "theological": 9208,
      "unions": 9209,
      "handful": 9210,
      "stability": 9211,
      "chan": 9212,
      "punjab": 9213,
      "segments": 9214,
      "##lly": 9215,
      "altar": 9216,
      "ignoring": 9217,
      "gesture": 9218,
      "monsters": 9219,
      "pastor": 9220,
      "##stone": 9221,
      "thighs": 9222,
      "unexpected": 9223,
      "operators": 9224,
      "abruptly": 9225,
      "coin": 9226,
      "compiled": 9227,
      "associates": 9228,
      "improving": 9229,
      "migration": 9230,

YARA rule 'network_reconnaissance': Network reconnaissance and scanning patterns [hacktools]

Medium
Category
YARA Match
Confidence
65% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · data/models/all-MiniLM-L6-v2/tokenizer.json (reported line 9367)May include surrounding context.

json
nquest": 9187,
      "dubbed": 9188,
      "##tv": 9189,
      "halt": 9190,
      "brave": 9191,
      "brunswick": 9192,
      "doi": 9193,
      "arched": 9194,
      "curtis": 9195,
      "divorced": 9196,
      "predominantly": 9197,
      "somerset": 9198,
      "streams": 9199,
      "ugly": 9200,
      "zoo": 9201,
      "horrible": 9202,
      "curved": 9203,
      "buenos": 9204,
      "fierce": 9205,
      "dictionary": 9206,
      "vector": 9207,
      "theological": 9208,
      "unions": 9209,
      "handful": 9210,
      "stability": 9211,
      "chan": 9212,
      "punjab": 9213,
      "segments": 9214,
      "##lly": 9215,
      "altar": 9216,
      "ignoring": 9217,
      "gesture": 9218,
      "monsters": 9219,
      "pastor": 9220,
      "##stone": 9221,
      "thighs": 9222,
      "unexpected": 9223,
      "operators": 9224,
      "abruptly": 9225,
      "coin": 9226,
      "compiled": 9227,
      "associates": 9228,
      "improving": 9229,
      "migration": 9230,

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The file's human-readable comments and docstrings consistently use Chinese, which effectively forces a specific language for operators or maintainers reading the skill. Under the stated policy, language-specific natural-language instructions should not be imposed without explicit opt-in or justification.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The hardcoded OpenAI endpoint confirms that embedding requests leave the local environment for a third-party service. The danger is contextual rather than inherently malicious: in a data-processing skill, remote transmission without strong safeguards can violate privacy expectations or compliance requirements.

Content

Scanner excerpt · src/embeddings.js (reported line 57)May include surrounding context.

js
return this.cache[cacheKey];
    }

    const response = await fetch('https://api.openai.com/v1/embeddings', {
      method: 'POST',
      headers: {
        'Content-Type': 'application/json',

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The hardcoded OpenAI endpoint confirms that embedding requests leave the local environment for a third-party service. The danger is contextual rather than inherently malicious: in a data-processing skill, remote transmission without strong safeguards can violate privacy expectations or compliance requirements.

Content

Scanner excerpt · src/embeddings.js (reported line 57)May include surrounding context.

js
return this.cache[cacheKey];
    }

    const response = await fetch('https://api.openai.com/v1/embeddings', {
      method: 'POST',
      headers: {
        'Content-Type': 'application/json',

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code sends arbitrary input text to the OpenAI Embeddings API, which is an external third party, without any built-in disclosure, consent check, or data-classification guardrail. If callers pass sensitive documents, secrets, or personal data, the module will exfiltrate that content off-host by design, creating a real privacy and data-handling risk in a RAG context.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The batch path uses the same external endpoint, so it carries the same trust-boundary risk with potentially greater volume. If exploited through misuse or misconfiguration, many records can be sent offsite before operators realize remote processing is occurring.

Content

Scanner excerpt · src/embeddings.js (reported line 107)May include surrounding context.

js
for (let i = 0; i < toProcess.length; i += this.batchSize) {
        const batch = toProcess.slice(i, i + this.batchSize);
        
        const response = await fetch('https://api.openai.com/v1/embeddings', {
          method: 'POST',
          headers: {
            'Content-Type': 'application/json',

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The batch path uses the same external endpoint, so it carries the same trust-boundary risk with potentially greater volume. If exploited through misuse or misconfiguration, many records can be sent offsite before operators realize remote processing is occurring.

Content

Scanner excerpt · src/embeddings.js (reported line 107)May include surrounding context.

js
for (let i = 0; i < toProcess.length; i += this.batchSize) {
        const batch = toProcess.slice(i, i + this.batchSize);
        
        const response = await fetch('https://api.openai.com/v1/embeddings', {
          method: 'POST',
          headers: {
            'Content-Type': 'application/json',

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The batch embedding path transmits all uncached texts to an external API with no warning or consent mechanism. In practice this can leak large volumes of internal corpus data at once, making the privacy impact higher than the single-text path because many documents may be uploaded in one operation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code sends full document content to an external embedding provider via embeddingProvider.embed(content) without any visible consent, minimization, or trust-boundary checks in this module. If documents contain sensitive or proprietary data, indexing them can disclose that data to a third party or another service boundary.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
src/embeddings.js:16