T08 · Insecure Dependencies
- Location
cli/install.js:45- Finding
Unpinned npm tooling and repository content are installed through npx
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This concise-writing skill is not clearly malicious, but its installer can persistently change agent configuration, add hooks, and enable mutable remote plugin content, so it needs Review before installation.
Install only if you are comfortable with Fasterizy making persistent changes to your agent setup. Prefer pinned package/repository versions, inspect the exact files and settings it will change, avoid running the CLI from privileged shells or automation, and be especially careful with Claude plugin installation because it can fetch and enable mutable remote content.
cli/install.js:45Unpinned npm tooling and repository content are installed through npx
cli/install-plugin.js:36Mutable remote repository is cloned into the Claude plugin cache and enabled automatically
cli/install-plugin.js:36Shell command injection through CLAUDE_CONFIG_DIR during plugin installation
The declared description presents Fasterizy as a behavioral skill for producing terse, answer-first prose in agent interactions, with chat-style toggles like '/fasterizy on/off'. The supplied code chunk, however, is not implementing response-formatting logic; it is a CLI entrypoint for operational management of the tool: install, update, start, stop, status, plugin promotion, and hook uninstallation. These are materially different capabilities involving local environment/configuration management and plugin lifecycle operations. While such setup tooling could support the described skill, this code chunk's actual primary purpose is administrative installation/configuration, which is not accurately represented by the declared purpose.
The declared description presents Fasterizy as a response-style skill that changes how answers are written. This code chunk does not implement response formatting behavior; instead, it provides CLI/helper functions for discovering Fasterizy-related installations and config files on disk. It traverses directories under the user's home directory and current working directory, checks for plugin markers, and reads files to confirm they contain 'fasterizy'. Those are materially different capabilities from the declared purpose and involve undeclared resource access to the local filesystem.
The declared description presents a conversational formatting/behavior skill for producing concise prose. The supplied code does not implement answer-style transformation, chat toggles, or prose compression behavior. Instead, it provides low-level filesystem utilities for JSON persistence and backups. This is a materially different primary purpose and includes undeclared resource access to the local filesystem.
The declared description presents a conversational formatting/behavior skill for producing concise answers. The supplied code does not implement answer-style changes, chat command handling, or prose compression. Instead, it scans hook configuration objects for entries whose command contains 'fasterizy' and strips them out for specific events. That is a materially different primary purpose: configuration inspection and removal of hooks, not response-style transformation. This constitutes an undeclared capability and a clear description-behavior mismatch.
The declared description presents this as a prose-style/verbosity behavior skill for chat responses. The supplied code does not implement response compression or answer-formatting behavior directly. Instead, it performs environment setup: installing hook scripts, patching Claude and Codex configuration, enabling hook features, and uninstalling those changes later. Those are materially different capabilities and triggers from the declared purpose. While these hooks may support the broader fasterizy feature, this code chunk itself is an installer/configuration manager, which is an undeclared operational behavior.
The declared description presents this as a behavioral/UX skill for producing terser answer-first prose in chat. The supplied code does not implement answer formatting, verbosity control, planning prose behavior, or chat command handling. Instead, it is an installation script that performs filesystem, git, and configuration-management actions to install and enable the Fasterizy plugin inside Claude Code. These are materially different capabilities and involve local file modification and network/git access that are not reflected in the declared purpose or permissions. This is a clear description-behavior mismatch.
The declared description presents this as a behavioral/prose skill for producing concise answers in coding-agent interactions, with chat commands to enable or disable it. The supplied code does not implement answer formatting or chat behavior. Instead, it performs local filesystem operations to install the skill into Cursor and Windsurf, including creating an always-on Windsurf rule file and copying/writing SKILL.md-derived content. Those installation and persistence behaviors are materially different from the declared end-user purpose and introduce undeclared capabilities and triggers.
The declared purpose presents the skill as a behavioral/prose transformation for answer formatting. This code chunk does not implement answer compression or response-style logic; instead, it performs installation and environment integration tasks for that skill across multiple coding agents. Those installer behaviors are not reflected in the declared description or permissions. While installer code can be a supporting component of a skill package, the prompt asks whether the declared description accurately represents what this supplied code chunk actually does, and it does not.
The declared description describes a conversational formatting/verbosity skill for coding-agent responses, with chat triggers to enable or disable terse output. The supplied code does not implement response-style modification or chat behavior. Instead, it performs local diagnostic/status reporting: checks a runtime flag, reads package.json, searches filesystem roots for installs, and reports plugin cache locations. These are materially different capabilities and involve local filesystem inspection that is not reflected in the declared purpose.
The declared description presents this as a chat/agent behavior skill for producing terser answers and responding to slash commands. The supplied code does not implement answer formatting, trigger handling, or prose transformation. Instead, it is an updater utility for the fasterizy package: it enumerates installations, spawns an external command to update them, checks cache locations, and prints operational guidance. That is a materially different primary purpose and includes undeclared capabilities involving subprocess execution and filesystem/install discovery.
The code installs persistent command hooks that execute on every session start and user prompt submission, even though the package is described as a terse-answer formatting skill. Running arbitrary local scripts on those events provides a durable execution foothold with access to user interaction flow, which is disproportionately powerful for the stated functionality.
This code executes Git commands and performs a network-backed git clone from GitHub, giving the skill software installation capability unrelated to formatting responses. That expands the attack surface substantially: a compromised repo, manipulated dependency source, or social-engineered install path could result in untrusted code being persisted into the Claude plugin environment.
The installer clones a repository, writes known_marketplaces.json, installed_plugins.json, and settings.json, and enables the plugin persistently in Claude's configuration. For a skill whose stated purpose is terse answer formatting, these privileged installation and persistence actions are far broader than necessary and create a dangerous trust boundary violation if the repository or local source is malicious or tampered with.
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
Concrete triggers:
- Destructive commands: \`rm -rf\`, \`git push --force\`, \`git reset --hard\`, \`DROP TABLE\`, truncate.
- Credentials, tokens, keys, secrets — generation, rotation, or exposure.
- Database migrations, especially on production or shared environments.
- Infrastructure changes affecting production traffic.
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
Concrete triggers:
- Destructive commands: \`rm -rf\`, \`git push --force\`, \`git reset --hard\`, \`DROP TABLE\`, truncate.
- Credentials, tokens, keys, secrets — generation, rotation, or exposure.
- Database migrations, especially on production or shared environments.
- Infrastructure changes affecting production traffic.
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
Concrete triggers:
- Destructive commands: \`rm -rf\`, \`git push --force\`, \`git reset --hard\`, \`DROP TABLE\`, truncate.
- Credentials, tokens, keys, secrets — generation, rotation, or exposure.
- Database migrations, especially on production or shared environments.
- Infrastructure changes affecting production traffic.
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
Concrete triggers:
- Destructive commands: \`rm -rf\`, \`git push --force\`, \`git reset --hard\`, \`DROP TABLE\`, truncate.
- Credentials, tokens, keys, secrets — generation, rotation, or exposure.
- Database migrations, especially on production or shared environments.
- Infrastructure changes affecting production traffic.
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
Concrete triggers:
- Destructive commands: \`rm -rf\`, \`git push --force\`, \`git reset --hard\`, \`DROP TABLE\`, truncate.
- Credentials, tokens, keys, secrets — generation, rotation, or exposure.
- Database migrations, especially on production or shared environments.
- Infrastructure changes affecting production traffic.
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
Concrete triggers:
- Destructive commands: \`rm -rf\`, \`git push --force\`, \`git reset --hard\`, \`DROP TABLE\`, truncate.
- Credentials, tokens, keys, secrets — generation, rotation, or exposure.
- Database migrations, especially on production or shared environments.
- Infrastructure changes affecting production traffic.
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
> **Warning:** This removes all contents of the target directory with no undo. Confirm host and path before running.
> \`\`\`bash
> rm -rf /srv/app/uploads/*
> \`\`\`
> After the user confirms they are on the right machine and have a backup if needed, continue in fasterizy style for what comes next.
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
> **Warning:** This removes all contents of the target directory with no undo. Confirm host and path before running.
> \`\`\`bash
> rm -rf /srv/app/uploads/*
> \`\`\`
> After the user confirms they are on the right machine and have a backup if needed, continue in fasterizy style for what comes next.
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
> **Warning:** This removes all contents of the target directory with no undo. Confirm host and path before running.
> \`\`\`bash
> rm -rf /srv/app/uploads/*
> \`\`\`
> After the user confirms they are on the right machine and have a backup if needed, continue in fasterizy style for what comes next.
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
> **Warning:** This removes all contents of the target directory with no undo. Confirm host and path before running.
> \`\`\`bash
> rm -rf /srv/app/uploads/*
> \`\`\`
> After the user confirms they are on the right machine and have a backup if needed, continue in fasterizy style for what comes next.
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
> **Warning:** This removes all contents of the target directory with no undo. Confirm host and path before running.
> \`\`\`bash
> rm -rf /srv/app/uploads/*
> \`\`\`
> After the user confirms they are on the right machine and have a backup if needed, continue in fasterizy style for what comes next.
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
> **Warning:** This removes all contents of the target directory with no undo. Confirm host and path before running.
> \`\`\`bash
> rm -rf /srv/app/uploads/*
> \`\`\`
> After the user confirms they are on the right machine and have a backup if needed, continue in fasterizy style for what comes next.
Detected: suspicious.dangerous_exec