Back to plugin

Security audit

Corpus RAG & KG Search

Security checks for vulnerabilities and agentic risk

Overview

This plugin coherently provides authenticated private corpus and knowledge-graph search, with credential use and token caching that are disclosed and purpose-aligned.

Install only if you intend to connect OpenClaw to this private corpus service and are comfortable storing its clientSecret, dataAuthKey, and cached accessToken in OpenClaw configuration. Confirm the baseUrl points to a service you trust, because search queries and auth headers are sent there.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.