T03 · Remote Payload Retrieval and Execution
- Location
README.md:44- Finding
Mutable Remote Installation Scripts Are Executed Directly
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill appears to be a real AI-agent runtime installer, but its install/update flow asks users to execute mutable remote scripts and unverified binaries with broad local authority.
Review before installing. Prefer downloading a versioned release, verifying a published checksum or signature, and running without administrator/root privileges. Treat ~/.fastclaw as sensitive because it may contain API keys, conversations, agent configuration, and long-term memory; back it up before deletion and avoid entering secrets or regulated data until storage, authentication, and provider-data handling are clear.
README.md:44Mutable Remote Installation Scripts Are Executed Directly
scripts/install.sh:43Downloaded Native Binary Is Installed Without Integrity Verification
templates/SOUL.md:84Agent Template Automatically Persists Conversation-Derived Long-Term Memory
Piping curl output directly into bash is a chaining pattern that turns remote content into immediate code execution with no review boundary. In installation documentation, this materially increases the risk of supply-chain compromise and accidental execution of altered scripts.
curl -fsSL https://raw.githubusercontent.com/fastclaw-ai/fastclaw/main/install.sh | bash
Although not malicious parameter abuse, rm -rf ~/.fastclaw is still a dangerous destructive command because it irreversibly deletes all local FastClaw data, including agent state and credentials, with no confirmation. In documentation for an agent runtime, users may copy-paste such commands during troubleshooting, making accidental data loss plausible.
# 停止 FastClaw 后执行
rm -rf ~/.fastclaw
Although not malicious parameter abuse, rm -rf ~/.fastclaw is still a dangerous destructive command because it irreversibly deletes all local FastClaw data, including agent state and credentials, with no confirmation. In documentation for an agent runtime, users may copy-paste such commands during troubleshooting, making accidental data loss plausible.
# 停止 FastClaw 后执行
rm -rf ~/.fastclaw
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
pkill fastclaw
# 删除程序
sudo rm /usr/local/bin/fastclaw
# (可选)删除用户数据
rm -rf ~/.fastclaw
This command forcefully and recursively deletes the application's entire user data directory, including potential API keys and agent memories, without confirmation. In a troubleshooting/uninstall section, that creates a real risk of accidental irreversible data destruction even if the scope is intended.
sudo rm /usr/local/bin/fastclaw
rm -rf ~/.fastclaw
---
This command forcefully and recursively deletes the application's entire user data directory, including potential API keys and agent memories, without confirmation. In a troubleshooting/uninstall section, that creates a real risk of accidental irreversible data destruction even if the scope is intended.
sudo rm /usr/local/bin/fastclaw
rm -rf ~/.fastclaw
---
The same chaining issue appears in the update path, where users are likely to run commands reflexively. That makes exploitation potentially broad and persistent because a compromised updater can replace trusted local binaries or alter configuration.
# macOS/Linux
curl -fsSL https://raw.githubusercontent.com/fastclaw-ai/fastclaw/main/install.sh | bash
# Windows - 重新下载最新版本即可
The documented curl | bash pattern is a classic unsafe command chain because it streams network content directly into a shell interpreter. This removes opportunities for integrity verification, human review, and safe failure handling, making supply-chain compromise or content tampering significantly more dangerous.
#!/bin/bash
# FastClaw macOS/Linux 一键安装脚本
# 运行方式:
# curl -fsSL https://raw.githubusercontent.com/fastclaw-ai/fastclaw/main/install.sh | bash
set -e
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
# 解压
echo "[2/3] Extracting..."
tar -xzf "${INSTALL_DIR}/fastclaw.tar.gz" -C "${INSTALL_DIR}"
rm "${INSTALL_DIR}/fastclaw.tar.gz"
# 安装到 PATH
if [[ "$OSTYPE" == "darwin"* ]]; then
The README instructs users to fetch and immediately execute a remote installer via PowerShell/Bash pipe execution, which removes any opportunity to inspect the script before execution. If the upstream repository, hosting account, or network path is compromised, users could run arbitrary code with their local privileges, and on Windows the instructions explicitly ask for administrator PowerShell, increasing blast radius.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# macOS
tar -xzf fastclaw_darwin_arm64.tar.gz
sudo mv fastclaw /usr/local/bin/
# Linux
tar -xzf fastclaw_linux_amd64.tar.gz
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# macOS
tar -xzf fastclaw_darwin_arm64.tar.gz
sudo mv fastclaw /usr/local/bin/
# Linux
tar -xzf fastclaw_linux_amd64.tar.gz
The setup guide tells users to enter API keys and documents that keys are stored in ~/.fastclaw/apikeys.json, but gives no warning about protecting that file, least-privilege permissions, or avoiding accidental disclosure. This can lead to credential leakage through backups, shared machines, screenshots, malware, or repository commits, exposing paid API access and potentially sensitive prompts/data sent through the service.
The README includes destructive deletion commands for user data and uninstall steps without a strong warning that they permanently erase configuration, agents, memories, and API keys. Users may copy-paste these commands during troubleshooting or uninstall and lose all data irreversibly, especially because recursive force deletion suppresses confirmation.
The skill advertises installation and operation of a runtime with a web UI and the static analyzer detected shell-capable behavior, yet the manifest does not declare any explicit tool scope such as permissions or allowed-tools. This creates a trust and containment gap: consumers cannot accurately assess what execution capabilities the skill may use, increasing the risk of unexpected command execution or broader host interaction during install or runtime.
The skill encourages users to configure API keys, use multiple external LLM providers, and manage conversations through a browser-based interface, but it provides no warning that prompts, conversation history, and secrets may be transmitted to third-party services or exposed via the local web dashboard. Users may unknowingly enter sensitive business data or credentials, leading to confidentiality, retention, or access-control risks.
This shell script contains user-facing natural-language instructions and status text in Chinese, including the title, usage notes, and completion guidance. Because it forces a specific language for user interaction without opt-in or justification, it violates the language/locale policy criterion.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
echo ""
echo "Note: /usr/local/bin is not writable."
echo "Add '${INSTALL_DIR}' to your PATH, or run:"
echo " sudo mv ${INSTALL_DIR}/fastclaw /usr/local/bin/fastclaw"
fi
else
if [[ -w "/usr/local/bin" ]]; then
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
echo ""
echo "Note: /usr/local/bin is not writable."
echo "Add '${INSTALL_DIR}' to your PATH, or run:"
echo " sudo mv ${INSTALL_DIR}/fastclaw /usr/local/bin/fastclaw"
fi
else
if [[ -w "/usr/local/bin" ]]; then
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
echo ""
echo "Note: /usr/local/bin is not writable."
echo "Add '${INSTALL_DIR}' to your PATH, or run:"
echo " sudo mv ${INSTALL_DIR}/fastclaw /usr/local/bin/fastclaw"
fi
else
if [[ -w "/usr/local/bin" ]]; then
The template tells agents to proactively update long-term memory after every conversation, but it does not require notice, consent, or any filtering for sensitive data. This creates a clear privacy and data-retention risk because user preferences, project details, or incidental personal data may be stored persistently without the user's awareness.
The memory section explicitly encourages persisting user preferences, project context, and todo items into long-term storage without defining sensitivity boundaries, minimization rules, or exclusions for secrets and personal data. In an agent runtime, this is especially risky because routine conversations can contain API keys, internal project details, or personal information that would then be retained and potentially exposed later.
The skill’s natural-language name, description, and system prompt are all written exclusively in Chinese, which implies a fixed language experience without any visible user opt-in or locale selection. Under the policy, forcing a specific language is a violation unless the locale constraint is explicitly justified or the user is offered a choice.
The skill documentation forces a single language presentation throughout the file and does not offer multilingual options or user opt-in. Under the stated policy, imposing a specific language without choice can be a natural-language policy violation unless clearly justified as region-specific.
The command fetches a remote script from GitHub and executes it immediately via bash. This creates a classic supply-chain/code-execution risk: any compromise of the repository, maintainer account, branch, or served content leads directly to arbitrary local command execution.
curl -fsSL https://raw.githubusercontent.com/fastclaw-ai/fastclaw/main/install.sh | bash
No suspicious patterns detected.