Back to skill

Security audit

AI Agent Runtime

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to be a real AI-agent runtime installer, but its install/update flow asks users to execute mutable remote scripts and unverified binaries with broad local authority.

Review before installing. Prefer downloading a versioned release, verifying a published checksum or signature, and running without administrator/root privileges. Treat ~/.fastclaw as sensitive because it may contain API keys, conversations, agent configuration, and long-term memory; back it up before deletion and avoid entering secrets or regulated data until storage, authentication, and provider-data handling are clear.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
README.md:44
Finding

Mutable Remote Installation Scripts Are Executed Directly

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
scripts/install.sh:43
Finding

Downloaded Native Binary Is Installed Without Integrity Verification

Content
View full analysis
Remediation
View remediation

T02 · Agent Memory Poisoning

Warning
Location
templates/SOUL.md:84
Finding

Agent Template Automatically Persists Conversation-Derived Long-Term Memory

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (28)

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

Piping curl output directly into bash is a chaining pattern that turns remote content into immediate code execution with no review boundary. In installation documentation, this materially increases the risk of supply-chain compromise and accidental execution of altered scripts.

Content

Scanner excerpt · README.md (reported line 85)May include surrounding context.

方式一:终端一键安装

bash
curl -fsSL https://raw.githubusercontent.com/fastclaw-ai/fastclaw/main/install.sh | bash

方式二:手动安装

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Although not malicious parameter abuse, rm -rf ~/.fastclaw is still a dangerous destructive command because it irreversibly deletes all local FastClaw data, including agent state and credentials, with no confirmation. In documentation for an agent runtime, users may copy-paste such commands during troubleshooting, making accidental data loss plausible.

Content

Scanner excerpt · README.md (reported line 234)May include surrounding context.

bash
# 停止 FastClaw 后执行
rm -rf ~/.fastclaw

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Although not malicious parameter abuse, rm -rf ~/.fastclaw is still a dangerous destructive command because it irreversibly deletes all local FastClaw data, including agent state and credentials, with no confirmation. In documentation for an agent runtime, users may copy-paste such commands during troubleshooting, making accidental data loss plausible.

Content

Scanner excerpt · README.md (reported line 234)May include surrounding context.

bash
# 停止 FastClaw 后执行
rm -rf ~/.fastclaw

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · README.md (reported line 254)May include surrounding context.

md
pkill fastclaw

# 删除程序
sudo rm /usr/local/bin/fastclaw

# (可选)删除用户数据
rm -rf ~/.fastclaw

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

This command forcefully and recursively deletes the application's entire user data directory, including potential API keys and agent memories, without confirmation. In a troubleshooting/uninstall section, that creates a real risk of accidental irreversible data destruction even if the scope is intended.

Content

Scanner excerpt · README.md (reported line 257)May include surrounding context.

sudo rm /usr/local/bin/fastclaw

(可选)删除用户数据

rm -rf ~/.fastclaw

text

---

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

This command forcefully and recursively deletes the application's entire user data directory, including potential API keys and agent memories, without confirmation. In a troubleshooting/uninstall section, that creates a real risk of accidental irreversible data destruction even if the scope is intended.

Content

Scanner excerpt · README.md (reported line 257)May include surrounding context.

sudo rm /usr/local/bin/fastclaw

(可选)删除用户数据

rm -rf ~/.fastclaw

text

---

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The same chaining issue appears in the update path, where users are likely to run commands reflexively. That makes exploitation potentially broad and persistent because a compromised updater can replace trusted local binaries or alter configuration.

Content

Scanner excerpt · README.md (reported line 268)May include surrounding context.

bash
# macOS/Linux
curl -fsSL https://raw.githubusercontent.com/fastclaw-ai/fastclaw/main/install.sh | bash

# Windows - 重新下载最新版本即可

Chaining Abuse

High
Category
Tool Misuse
Confidence
96% confidence
Finding

The documented curl | bash pattern is a classic unsafe command chain because it streams network content directly into a shell interpreter. This removes opportunities for integrity verification, human review, and safe failure handling, making supply-chain compromise or content tampering significantly more dangerous.

Content

Scanner excerpt · scripts/install.sh (reported line 4)May include surrounding context.

sh
#!/bin/bash
# FastClaw macOS/Linux 一键安装脚本
# 运行方式:
# curl -fsSL https://raw.githubusercontent.com/fastclaw-ai/fastclaw/main/install.sh | bash

set -e

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/install.sh (reported line 51)May include surrounding context.

sh
# 解压
echo "[2/3] Extracting..."
tar -xzf "${INSTALL_DIR}/fastclaw.tar.gz" -C "${INSTALL_DIR}"
rm "${INSTALL_DIR}/fastclaw.tar.gz"

# 安装到 PATH
if [[ "$OSTYPE" == "darwin"* ]]; then

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The README instructs users to fetch and immediately execute a remote installer via PowerShell/Bash pipe execution, which removes any opportunity to inspect the script before execution. If the upstream repository, hosting account, or network path is compromised, users could run arbitrary code with their local privileges, and on Windows the instructions explicitly ask for administrator PowerShell, increasing blast radius.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 105)May include surrounding context.

bash
# macOS
tar -xzf fastclaw_darwin_arm64.tar.gz
sudo mv fastclaw /usr/local/bin/

# Linux
tar -xzf fastclaw_linux_amd64.tar.gz

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 109)May include surrounding context.

bash
# macOS
tar -xzf fastclaw_darwin_arm64.tar.gz
sudo mv fastclaw /usr/local/bin/

# Linux
tar -xzf fastclaw_linux_amd64.tar.gz

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The setup guide tells users to enter API keys and documents that keys are stored in ~/.fastclaw/apikeys.json, but gives no warning about protecting that file, least-privilege permissions, or avoiding accidental disclosure. This can lead to credential leakage through backups, shared machines, screenshots, malware, or repository commits, exposing paid API access and potentially sensitive prompts/data sent through the service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README includes destructive deletion commands for user data and uninstall steps without a strong warning that they permanently erase configuration, agents, memories, and API keys. Users may copy-paste these commands during troubleshooting or uninstall and lose all data irreversibly, especially because recursive force deletion suppresses confirmation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill advertises installation and operation of a runtime with a web UI and the static analyzer detected shell-capable behavior, yet the manifest does not declare any explicit tool scope such as permissions or allowed-tools. This creates a trust and containment gap: consumers cannot accurately assess what execution capabilities the skill may use, increasing the risk of unexpected command execution or broader host interaction during install or runtime.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill encourages users to configure API keys, use multiple external LLM providers, and manage conversations through a browser-based interface, but it provides no warning that prompts, conversation history, and secrets may be transmitted to third-party services or exposed via the local web dashboard. Users may unknowingly enter sensitive business data or credentials, leading to confidentiality, retention, or access-control risks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This shell script contains user-facing natural-language instructions and status text in Chinese, including the title, usage notes, and completion guidance. Because it forces a specific language for user interaction without opt-in or justification, it violates the language/locale policy criterion.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 254)May include surrounding context.

md
echo ""
        echo "Note: /usr/local/bin is not writable."
        echo "Add '${INSTALL_DIR}' to your PATH, or run:"
        echo "  sudo mv ${INSTALL_DIR}/fastclaw /usr/local/bin/fastclaw"
    fi
else
    if [[ -w "/usr/local/bin" ]]; then

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/install.sh (reported line 61)May include surrounding context.

sh
echo ""
        echo "Note: /usr/local/bin is not writable."
        echo "Add '${INSTALL_DIR}' to your PATH, or run:"
        echo "  sudo mv ${INSTALL_DIR}/fastclaw /usr/local/bin/fastclaw"
    fi
else
    if [[ -w "/usr/local/bin" ]]; then

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/install.sh (reported line 70)May include surrounding context.

sh
echo ""
        echo "Note: /usr/local/bin is not writable."
        echo "Add '${INSTALL_DIR}' to your PATH, or run:"
        echo "  sudo mv ${INSTALL_DIR}/fastclaw /usr/local/bin/fastclaw"
    fi
else
    if [[ -w "/usr/local/bin" ]]; then

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The template tells agents to proactively update long-term memory after every conversation, but it does not require notice, consent, or any filtering for sensitive data. This creates a clear privacy and data-retention risk because user preferences, project details, or incidental personal data may be stored persistently without the user's awareness.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The memory section explicitly encourages persisting user preferences, project context, and todo items into long-term storage without defining sensitivity boundaries, minimization rules, or exclusions for secrets and personal data. In an agent runtime, this is especially risky because routine conversations can contain API keys, internal project details, or personal information that would then be retained and potentially exposed later.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill’s natural-language name, description, and system prompt are all written exclusively in Chinese, which implies a fixed language experience without any visible user opt-in or locale selection. Under the policy, forcing a specific language is a violation unless the locale constraint is explicitly justified or the user is offered a choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill documentation forces a single language presentation throughout the file and does not offer multilingual options or user opt-in. Under the stated policy, imposing a specific language without choice can be a natural-language policy violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

External Script Fetching

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The command fetches a remote script from GitHub and executes it immediately via bash. This creates a classic supply-chain/code-execution risk: any compromise of the repository, maintainer account, branch, or served content leads directly to arbitrary local command execution.

Content

Scanner excerpt · README.md (reported line 85)May include surrounding context.

方式一:终端一键安装

bash
curl -fsSL https://raw.githubusercontent.com/fastclaw-ai/fastclaw/main/install.sh | bash

方式二:手动安装

Static analysis

No suspicious patterns detected.