BoundBench

RAGFlow

RAG engine with agent workflows, tools and code execution

github.com/infiniflow/ragflow · 2026-10-05 · 2400ca8

Defense-in-depth score

2.9 / 10

Minimal

RAGFlow lets anyone who can build an agent give it web, SQL, email, HTTP and MCP tools that run on every model decision with no human approval, while the same sessions read uploaded documents, web pages and messages from visitors of shared agent links. The strongest controls are a pinned-IP SSRF guard on the URL tools, a tenant-scoped tool binding, and code execution that stays off until an operator deploys a sandbox; nothing limits what a prompt-injected agent does with the tools it was given. Credentials are stored in plaintext and agent tool calls leave no durable audit record. Treat every agent that combines document or web input with email, HTTP or MCP write tools as exposed to whoever can get text into its context.

Key gaps (1)

  1. A hijacked agent can read private knowledge-base or database content and send it out or take irreversible sends with no human involved. C5 · Untrusted input blast radius

Criteria

C1 Identity & least privilege

Minimal 0.40 / 1.00

Agents run with the authority of the tenant that built them: tool credentials (SMTP, SQL, API keys, MCP headers) are typed into the workflow by the designer and used for every caller, including anonymous visitors of a shared agent link. Code does scope data access: MCP servers are loaded only if they belong to the run's tenant, and agentic retrieval refuses dataset ids outside the conversation's bound scope. There is no per-requesting-user check on tools and no narrower credential for read versus write. The shipped deployment enables self-registration and bootstraps an administrator account at start-up.

C2 Approval gates

Minimal 0.05 / 1.00

There is no approval step anywhere on the agent tool path. The canvas agent hands its tool list straight to an automatic reason-act loop, so email sends, HTTP calls, SQL queries, code execution and MCP tools all run as soon as the model asks. A human-input node exists, but only as a workflow step the designer places, not as a gate on tool calls. An approval middleware exists in an unused internal package that no production code imports.

C3 Tool & action scoping

Moderate 0.50 / 1.00

URL-fetching tools resolve the host, reject private, loopback and metadata addresses, and pin the connection to the vetted IP, which closes the usual SSRF tricks; the HTTP component also refuses redirects. SQL is limited to reads by a keyword-level statement filter with a row cap, but email recipients are whatever the model chooses, code execution takes arbitrary scripts, and MCP arguments are passed through unchecked. Each agent only gets the tools its designer listed, unknown tool names are rejected, and the model cannot add tools.

C4 Code-execution isolation

Moderate 0.50 / 1.00

Model-written Python or JavaScript runs only through a sandbox provider. The default provider points at a separate executor service that the shipped compose file does not start, so code execution fails until an operator deploys it, and there is no silent fallback to the host. When deployed, it runs each script in a stock Docker container with no network, 256 MB of memory and a 10-second timeout; seccomp is off by default and the manager itself runs privileged with the Docker socket. An administrator can instead pick a 'local' provider that runs code directly on the server with only a scrubbed environment. The agentic-RAG chat also has a JavaScript tool, but it runs in an embedded interpreter whose only capability is printing output.

C5 Untrusted input blast radius

Minimal 0.00 / 1.00

Nothing structural limits a hijacked agent. Retrieved document chunks, web results, crawler pages and MCP results all enter the model's context as ordinary tool output, with no taint tracking, no provenance-based gating and no approval before egress or sends. A single session can read untrusted documents, query private knowledge bases and databases, and send email or call HTTP and MCP endpoints. Shared agent links and optional chat-channel connectors let outside users talk to agents that hold the owner's tools, with no sender allowlist.

C6 Memory, context & configuration integrity

Minimal 0.20 / 1.00

Everything uploaded to a knowledge base persists and is retrieved into agent context for every user of that knowledge base, and agents can be configured to save each user input and answer into a memory store that later runs read back. Writes are not validated or reviewed. Isolation between tenants is enforced in queries, but within a tenant memory is shared across end users unless a user id happens to be supplied. Retrieved chunks carry document ids and can be inspected and deleted in the UI.

C7 Third-party extensions

Minimal 0.35 / 1.00

The only runtime extensions are MCP servers, which RAGFlow reaches over HTTP rather than launching locally, so no third-party code runs inside the RAGFlow process. A tenant user registers a server by URL, and an agent designer picks specific tools from it; the tool schemas captured at configuration time are what the agent uses later. Nothing pins or verifies the server's behaviour, and its tool descriptions go to the model verbatim. The server only receives its own configured headers plus whatever arguments the model sends.

C8 Secrets & sensitive-data protection

Minimal 0.17 / 1.00

Provider API keys and tool credentials are stored as plaintext database columns and workflow parameters, with no masking type or general log filter. A few paths are careful: the HTTP access log drops query strings and tool errors scrub credential-named URL parameters. Sandbox runs get a scrubbed environment, and credentials are not placed in prompts. Verbose LLM request logging and per-tenant tracing exports are opt-in.

C9 Audit & traceability

Minimal 0.30 / 1.00

Each workflow node emits a structured finished event with its inputs, outputs (including the agent's tool calls) and timing, but these events are streamed to the client rather than stored. What persists is the conversation's user messages and answers in the database, plus run checkpoints that expire after 24 hours. Code-execution calls are logged only at debug level. There is no actor attribution beyond the session, no record of individual tool calls that survives the run, and nothing tamper-evident.

C10 Limits & kill switch

Minimal 0.45 / 1.00

Canvas agents default to five reason-act rounds, sub-agents nest at most eight deep, workflow loops stop at 1,024 iterations, and code execution and MCP calls have timeouts. There is no token or spend cap and no run-level wall-clock limit, and each sub-agent gets a fresh round budget. The model may pass its own code-execution timeout, up to ten minutes. Cancelling a session sets a flag that is polled every half second and cancels the run's context, which interrupts the JavaScript interpreter and kills local code-execution process groups.