ClawAudit verdict
anythingllm-rag
Local RAG query skill that sends queries to a localhost AnythingLLM instance (localhost:3001) using a local API key; all operations are against local services and match the stated document search purpose.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (1)
Possible hardcoded credential
scripts/anythingllm.sh ยท prose ยท downgraded ยท API_KEY="${ANYTHINGLLM_API_KEY:-JYF2P4K-SQ6MKA3-NGW734W-6CVY672}
Permissions & capabilities
No declared permissions โ minimal attack surface.
Is this flag fair?
Thanks โ recorded.