Back to skill

Security audit

Fasterizy

Security checks for vulnerabilities and agentic risk

Overview

This concise-writing skill is not clearly malicious, but its installer can persistently change agent configuration, add hooks, and enable mutable remote plugin content, so it needs Review before installation.

Install only if you are comfortable with Fasterizy making persistent changes to your agent setup. Prefer pinned package/repository versions, inspect the exact files and settings it will change, avoid running the CLI from privileged shells or automation, and be especially careful with Claude plugin installation because it can fetch and enable mutable remote content.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T08 · Insecure Dependencies

Error
Location
cli/install.js:45
Finding

Unpinned npm tooling and repository content are installed through npx

Content
View full analysis
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
cli/install-plugin.js:36
Finding

Mutable remote repository is cloned into the Claude plugin cache and enabled automatically

Content
View full analysis
{ const parts = src.split(path.sep); return !parts.includes('.git') && !parts.includes('node_modules'); }, }); copied = true; } patchInstalledPlugins(claudeDir, installPath, fullSha, versionTag); const settingsResult = patc ...[truncated 2240 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
cli/install-plugin.js:36
Finding

Shell command injection through CLAUDE_CONFIG_DIR during plugin installation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (72)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents Fasterizy as a behavioral skill for producing terse, answer-first prose in agent interactions, with chat-style toggles like '/fasterizy on/off'. The supplied code chunk, however, is not implementing response-formatting logic; it is a CLI entrypoint for operational management of the tool: install, update, start, stop, status, plugin promotion, and hook uninstallation. These are materially different capabilities involving local environment/configuration management and plugin lifecycle operations. While such setup tooling could support the described skill, this code chunk's actual primary purpose is administrative installation/configuration, which is not accurately represented by the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description presents Fasterizy as a response-style skill that changes how answers are written. This code chunk does not implement response formatting behavior; instead, it provides CLI/helper functions for discovering Fasterizy-related installations and config files on disk. It traverses directories under the user's home directory and current working directory, checks for plugin markers, and reads files to confirm they contain 'fasterizy'. Those are materially different capabilities from the declared purpose and involve undeclared resource access to the local filesystem.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a conversational formatting/behavior skill for producing concise prose. The supplied code does not implement answer-style transformation, chat toggles, or prose compression behavior. Instead, it provides low-level filesystem utilities for JSON persistence and backups. This is a materially different primary purpose and includes undeclared resource access to the local filesystem.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents a conversational formatting/behavior skill for producing concise answers. The supplied code does not implement answer-style changes, chat command handling, or prose compression. Instead, it scans hook configuration objects for entries whose command contains 'fasterizy' and strips them out for specific events. That is a materially different primary purpose: configuration inspection and removal of hooks, not response-style transformation. This constitutes an undeclared capability and a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents this as a prose-style/verbosity behavior skill for chat responses. The supplied code does not implement response compression or answer-formatting behavior directly. Instead, it performs environment setup: installing hook scripts, patching Claude and Codex configuration, enabling hook features, and uninstalling those changes later. Those are materially different capabilities and triggers from the declared purpose. While these hooks may support the broader fasterizy feature, this code chunk itself is an installer/configuration manager, which is an undeclared operational behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents this as a behavioral/UX skill for producing terser answer-first prose in chat. The supplied code does not implement answer formatting, verbosity control, planning prose behavior, or chat command handling. Instead, it is an installation script that performs filesystem, git, and configuration-management actions to install and enable the Fasterizy plugin inside Claude Code. These are materially different capabilities and involve local file modification and network/git access that are not reflected in the declared purpose or permissions. This is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents this as a behavioral/prose skill for producing concise answers in coding-agent interactions, with chat commands to enable or disable it. The supplied code does not implement answer formatting or chat behavior. Instead, it performs local filesystem operations to install the skill into Cursor and Windsurf, including creating an always-on Windsurf rule file and copying/writing SKILL.md-derived content. Those installation and persistence behaviors are materially different from the declared end-user purpose and introduce undeclared capabilities and triggers.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose presents the skill as a behavioral/prose transformation for answer formatting. This code chunk does not implement answer compression or response-style logic; instead, it performs installation and environment integration tasks for that skill across multiple coding agents. Those installer behaviors are not reflected in the declared description or permissions. While installer code can be a supporting component of a skill package, the prompt asks whether the declared description accurately represents what this supplied code chunk actually does, and it does not.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description describes a conversational formatting/verbosity skill for coding-agent responses, with chat triggers to enable or disable terse output. The supplied code does not implement response-style modification or chat behavior. Instead, it performs local diagnostic/status reporting: checks a runtime flag, reads package.json, searches filesystem roots for installs, and reports plugin cache locations. These are materially different capabilities and involve local filesystem inspection that is not reflected in the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents this as a chat/agent behavior skill for producing terser answers and responding to slash commands. The supplied code does not implement answer formatting, trigger handling, or prose transformation. Instead, it is an updater utility for the fasterizy package: it enumerates installations, spawns an external command to update them, checks cache locations, and prints operational guidance. That is a materially different primary purpose and includes undeclared capabilities involving subprocess execution and filesystem/install discovery.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code installs persistent command hooks that execute on every session start and user prompt submission, even though the package is described as a terse-answer formatting skill. Running arbitrary local scripts on those events provides a durable execution foothold with access to user interaction flow, which is disproportionately powerful for the stated functionality.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code executes Git commands and performs a network-backed git clone from GitHub, giving the skill software installation capability unrelated to formatting responses. That expands the attack surface substantially: a compromised repo, manipulated dependency source, or social-engineered install path could result in untrusted code being persisted into the Claude plugin environment.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The installer clones a repository, writes known_marketplaces.json, installed_plugins.json, and settings.json, and enables the plugin persistently in Claude's configuration. For a skill whose stated purpose is terse answer formatting, these privileged installation and persistence actions are far broader than necessary and create a dangerous trust boundary violation if the repository or local source is malicious or tampered with.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 114)May include surrounding context.

md
Concrete triggers:

- Destructive commands: \`rm -rf\`, \`git push --force\`, \`git reset --hard\`, \`DROP TABLE\`, truncate.
- Credentials, tokens, keys, secrets — generation, rotation, or exposure.
- Database migrations, especially on production or shared environments.
- Infrastructure changes affecting production traffic.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · hooks/skill-content.js (reported line 108)May include surrounding context.

js
Concrete triggers:

- Destructive commands: \`rm -rf\`, \`git push --force\`, \`git reset --hard\`, \`DROP TABLE\`, truncate.
- Credentials, tokens, keys, secrets — generation, rotation, or exposure.
- Database migrations, especially on production or shared environments.
- Infrastructure changes affecting production traffic.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · skills/fasterizy/SKILL.md (reported line 113)May include surrounding context.

md
Concrete triggers:

- Destructive commands: \`rm -rf\`, \`git push --force\`, \`git reset --hard\`, \`DROP TABLE\`, truncate.
- Credentials, tokens, keys, secrets — generation, rotation, or exposure.
- Database migrations, especially on production or shared environments.
- Infrastructure changes affecting production traffic.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 114)May include surrounding context.

md
Concrete triggers:

- Destructive commands: \`rm -rf\`, \`git push --force\`, \`git reset --hard\`, \`DROP TABLE\`, truncate.
- Credentials, tokens, keys, secrets — generation, rotation, or exposure.
- Database migrations, especially on production or shared environments.
- Infrastructure changes affecting production traffic.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · hooks/skill-content.js (reported line 108)May include surrounding context.

js
Concrete triggers:

- Destructive commands: \`rm -rf\`, \`git push --force\`, \`git reset --hard\`, \`DROP TABLE\`, truncate.
- Credentials, tokens, keys, secrets — generation, rotation, or exposure.
- Database migrations, especially on production or shared environments.
- Infrastructure changes affecting production traffic.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · skills/fasterizy/SKILL.md (reported line 113)May include surrounding context.

md
Concrete triggers:

- Destructive commands: \`rm -rf\`, \`git push --force\`, \`git reset --hard\`, \`DROP TABLE\`, truncate.
- Credentials, tokens, keys, secrets — generation, rotation, or exposure.
- Database migrations, especially on production or shared environments.
- Infrastructure changes affecting production traffic.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
100% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 124)May include surrounding context.

md
> **Warning:** This removes all contents of the target directory with no undo. Confirm host and path before running.
> \`\`\`bash
> rm -rf /srv/app/uploads/*
> \`\`\`
> After the user confirms they are on the right machine and have a backup if needed, continue in fasterizy style for what comes next.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
100% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · hooks/skill-content.js (reported line 118)May include surrounding context.

js
> **Warning:** This removes all contents of the target directory with no undo. Confirm host and path before running.
> \`\`\`bash
> rm -rf /srv/app/uploads/*
> \`\`\`
> After the user confirms they are on the right machine and have a backup if needed, continue in fasterizy style for what comes next.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
100% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · skills/fasterizy/SKILL.md (reported line 123)May include surrounding context.

md
> **Warning:** This removes all contents of the target directory with no undo. Confirm host and path before running.
> \`\`\`bash
> rm -rf /srv/app/uploads/*
> \`\`\`
> After the user confirms they are on the right machine and have a backup if needed, continue in fasterizy style for what comes next.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
100% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 124)May include surrounding context.

md
> **Warning:** This removes all contents of the target directory with no undo. Confirm host and path before running.
> \`\`\`bash
> rm -rf /srv/app/uploads/*
> \`\`\`
> After the user confirms they are on the right machine and have a backup if needed, continue in fasterizy style for what comes next.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
100% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · hooks/skill-content.js (reported line 118)May include surrounding context.

js
> **Warning:** This removes all contents of the target directory with no undo. Confirm host and path before running.
> \`\`\`bash
> rm -rf /srv/app/uploads/*
> \`\`\`
> After the user confirms they are on the right machine and have a backup if needed, continue in fasterizy style for what comes next.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
100% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · skills/fasterizy/SKILL.md (reported line 123)May include surrounding context.

md
> **Warning:** This removes all contents of the target directory with no undo. Confirm host and path before running.
> \`\`\`bash
> rm -rf /srv/app/uploads/*
> \`\`\`
> After the user confirms they are on the right machine and have a backup if needed, continue in fasterizy style for what comes next.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
cli/install-plugin.js:24

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
cli/install.js:46

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
cli/update.js:11