Back to skill

Security audit

fastcp

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward file-copy CLI wrapper, but users should verify the external installer and target drives before running real copy commands.

Before installing, prefer a pinned reviewed version or verified release checksum. Before copying, run --dry-run first, confirm each drive letter or mount point, and remember that normal fastcp commands write to every listed target.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:23
Finding

Unpinned Third-Party Installation Without Artifact Verification

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 23–29
Vulnerability Type: Unpinned and unverified third-party dependency installation
Risk Level: Medium

Vulnerable Code Snippet

markdown
## 安装 / Install

```bash
go install github.com/dongsheng123132/fastcp@latest

或从 GitHub Releases 下载二进制。/ Or grab a binary from GitHub Releases.

text

### Technical Analysis

The installation command uses the mutable `@latest` selector rather than an immutable, reviewed version or commit. Consequently, the code installed in the future may differ from the code that was assessed when the skill documentation was published.

The alternative instruction to download a binary from GitHub Releases also does not specify a fixed release, expected cryptographic checksum, or signature-verification procedure. The executable implementation and its dependency manifest are not included in the audited project, so their behavior and transitive dependencies cannot be verified from this artifact.

This creates a supply-chain trust boundary in which upstream repository control, release infrastructure, and dependencies determine the code ultimately executed by the user.

### Attack Path

1. An attacker compromises the upstream repository, maintainer account, release infrastructure, or a dependency used by the external project.
2. The attacker publishes a malicious version selected by `@latest`, or substitutes a malicious release binary.
3. A user or AI agent follows the documented installation instruction.
4. The package manager or user retrieves and executes the unreviewed component.
5. The malicious executable operates with the invoking user's permissions and can abuse its expected access to source and destination paths.

### Impact Assessment

Successful exploitation grants malicious upstream code the same privileges as the account running the installation or invoking `fastcp`. The practical scope may include reading, modifying, deleting, or disclosing files acce
...[truncated 475 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace @latest with a reviewed, fixed semantic version or immutable commit identifier.
  2. Document the exact approved release version and upgrade it only after security review.
  3. Publish SHA-256 or stronger checksums for every supported release artifact.
  4. Provide cryptographic signature or provenance verification instructions, such as Sigstore verification or signed release manifests.
  5. Pin and audit transitive dependencies in the upstream project, and use automated dependency and provenance scanning.
  6. Recommend executing the utility with the minimum filesystem permissions required for the selected source and destination directories.
  7. Where feasible, vendor or include the reviewed source and build instructions so the effective implementation can be audited alongside the skill.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation provides direct example commands that write to multiple target drives but does not prominently warn that running them will perform real writes to all listed destinations, including removable USB media. In an AI-tooling context where commands may be surfaced or invoked with limited human scrutiny, this increases the risk of accidental overwrites or unintended data propagation across multiple devices.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.