Security audit
Corpus RAG & KG Search
Security checks for vulnerabilities and agentic risk
Overview
This plugin coherently provides authenticated private corpus and knowledge-graph search, with credential use and token caching that are disclosed and purpose-aligned.
Install only if you intend to connect OpenClaw to this private corpus service and are comfortable storing its clientSecret, dataAuthKey, and cached accessToken in OpenClaw configuration. Confirm the baseUrl points to a service you trust, because search queries and auth headers are sent there.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
