T03 · Remote Payload Retrieval and Execution
- Location
README.md:50- Finding
Mutable Remote Installation Scripts Are Executed Without Review or Verification
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This FastClaw deployment skill is coherent, but its installer guidance asks users to run mutable remote scripts and unverified binaries with elevated privileges.
Review carefully before installing. Prefer manual, version-pinned downloads with published checksums or signatures; avoid running curl | bash or irm | iex from a mutable branch, especially in an Administrator shell. Protect or rotate any API keys stored under ~/.fastclaw, and treat rm -rf ~/.fastclaw as permanent deletion of local FastClaw data.
README.md:50Mutable Remote Installation Scripts Are Executed Without Review or Verification
scripts/install.sh:45Downloaded Native Binary Is Installed Without Cryptographic Integrity Verification
templates/SOUL.md:84Agent Template Encourages Unbounded Persistent Storage of Conversation-Derived Context
Piping network content directly into bash is a classic chaining hazard because it removes the user's chance to inspect the script before execution. In an installation guide, this pattern strongly increases the likelihood of widespread compromise if the upstream script is altered maliciously or accidentally.
curl -fsSL https://raw.githubusercontent.com/fastclaw-ai/fastclaw/main/install.sh | bash
Even though the path is scoped to the application's data directory, rm -rf ~/.fastclaw is an irreversible recursive delete command. In documentation for end users, copy-paste destructive commands without safeguards can cause accidental loss of configuration, memory, and stored secrets.
# 停止 FastClaw 后执行
rm -rf ~/.fastclaw
Even though the path is scoped to the application's data directory, rm -rf ~/.fastclaw is an irreversible recursive delete command. In documentation for end users, copy-paste destructive commands without safeguards can cause accidental loss of configuration, memory, and stored secrets.
# 停止 FastClaw 后执行
rm -rf ~/.fastclaw
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
pkill fastclaw
# 删除程序
sudo rm /usr/local/bin/fastclaw
# (可选)删除用户数据
rm -rf ~/.fastclaw
This command recursively deletes the application's user data directory during uninstall and may remove secrets and state irreversibly. While legitimate as an optional cleanup action, it should be treated as dangerous because users may not realize the full extent of data loss.
sudo rm /usr/local/bin/fastclaw
rm -rf ~/.fastclaw
---
This command recursively deletes the application's user data directory during uninstall and may remove secrets and state irreversibly. While legitimate as an optional cleanup action, it should be treated as dangerous because users may not realize the full extent of data loss.
sudo rm /usr/local/bin/fastclaw
rm -rf ~/.fastclaw
---
The same chaining pattern is used for updates, so a future repository compromise could turn routine upgrades into arbitrary code execution across existing installs. Because the URL points to a mutable branch path, users implicitly trust whatever content exists at update time.
# macOS/Linux
curl -fsSL https://raw.githubusercontent.com/fastclaw-ai/fastclaw/main/install.sh | bash
# Windows - 重新下载最新版本即可
The documented use of 'curl ... | bash' is a classic chaining pattern that turns network content directly into executed shell commands. In a deployment skill, this is especially dangerous because users may follow the documented one-liner without review, making any compromise of the upstream repository or account an instant code-execution event.
#!/bin/bash
# FastClaw macOS/Linux 一键安装脚本
# 运行方式:
# curl -fsSL https://raw.githubusercontent.com/fastclaw-ai/fastclaw/main/install.sh | bash
set -e
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
# 解压
echo "[2/3] Extracting..."
tar -xzf "${INSTALL_DIR}/fastclaw.tar.gz" -C "${INSTALL_DIR}"
rm "${INSTALL_DIR}/fastclaw.tar.gz"
# 安装到 PATH
if [[ "$OSTYPE" == "darwin"* ]]; then
The README instructs users to run a PowerShell one-liner that downloads and immediately executes a remote script via iex. This creates a direct remote-code-execution path if the upstream script, GitHub account, repository, or transport context is compromised, and the risk is amplified because the instructions recommend running it as Administrator.
The macOS/Linux install command pipes a fetched network script directly into bash, which executes unreviewed remote code immediately. If the hosting repo or distribution path is tampered with, users could execute arbitrary commands on their systems without any verification step.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# macOS
tar -xzf fastclaw_darwin_arm64.tar.gz
sudo mv fastclaw /usr/local/bin/
# Linux
tar -xzf fastclaw_linux_amd64.tar.gz
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# macOS
tar -xzf fastclaw_darwin_arm64.tar.gz
sudo mv fastclaw /usr/local/bin/
# Linux
tar -xzf fastclaw_linux_amd64.tar.gz
The documentation tells users to enter API keys and reveals that credentials are stored under ~/.fastclaw/apikeys.json, but it does not warn that these are sensitive secrets or discuss local file-permission and backup exposure risks. On shared systems or poorly secured environments, this can lead to credential disclosure and downstream account abuse.
The README provides rm -rf ~/.fastclaw as a cleanup step without a strong warning that it irreversibly deletes all local FastClaw data. Users may lose agent state, configuration, memories, and stored credentials if they copy-paste the command without understanding its effects.
The uninstall instructions include sudo rm and rm -rf commands but do not clearly warn about irreversible deletion or the risks of elevated privileges. This increases the chance of destructive user error and normalizes copy-pasting privileged shell commands from documentation.
sudo rm /usr/local/bin/fastclaw is a privileged destructive command. While uninstalling a known binary is legitimate, presenting elevated deletion commands without strong cautions can lead to harmful copy-paste behavior and makes mistakes under root privileges more dangerous.
pkill fastclaw
# 删除程序
sudo rm /usr/local/bin/fastclaw
# (可选)删除用户数据
rm -rf ~/.fastclaw
The skill advertises installation and deployment behavior and static analysis detected shell capability, but the manifest does not declare any explicit tool scope such as permissions or allowed-tools. That creates an authorization gap where an agent or platform may permit broader command execution than users expect, increasing the risk of unintended system changes during deployment.
The skill instructs users to configure third-party LLM API keys and routes them to external providers, but provides no warning about secret handling, data sharing, retention, or trust boundaries. Users may enter sensitive credentials and prompts into services they do not fully understand, which can lead to credential exposure or confidential data disclosure to external vendors.
On first-time installation, the script immediately creates directories, downloads an archive, extracts it, and may move a binary into a common PATH location without an explicit confirmation step. While typical for bootstrap installers, this reduces informed consent and increases the chance a user runs impactful filesystem changes they did not fully expect, especially when paired with a curl-to-shell usage pattern.
The installer downloads a release archive from the network and installs a binary into a user-controlled directory and potentially into /usr/local/bin, but it does so without any integrity verification such as a checksum or signature check. In the context of an installer, downloading and installing software is expected behavior, but the lack of authenticity verification means a compromised release channel, mirror, or build pipeline could deliver a trojaned binary.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
echo ""
echo "Note: /usr/local/bin is not writable."
echo "Add '${INSTALL_DIR}' to your PATH, or run:"
echo " sudo mv ${INSTALL_DIR}/fastclaw /usr/local/bin/fastclaw"
fi
else
if [[ -w "/usr/local/bin" ]]; then
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
echo ""
echo "Note: /usr/local/bin is not writable."
echo "Add '${INSTALL_DIR}' to your PATH, or run:"
echo " sudo mv ${INSTALL_DIR}/fastclaw /usr/local/bin/fastclaw"
fi
else
if [[ -w "/usr/local/bin" ]]; then
SQP-3 applies to natural-language policy issues in all file types, including markdown templates. The entire template defines the agent persona and workflow only in Chinese and includes no indication that language should be user-selected or that the locale restriction is intentional for a region-specific use case.
The template instructs the agent to modify MEMORY.md based on conversation content, which moves beyond passive persona/configuration into persistent state mutation. In a skill template, this can cause unexpected data retention or file writes without explicit user awareness or consent, increasing privacy and integrity risk.
No suspicious patterns detected.