Back to skill

Security audit

FastClaw AI部署工具

Security checks for vulnerabilities and agentic risk

Overview

This FastClaw deployment skill is coherent, but its installer guidance asks users to run mutable remote scripts and unverified binaries with elevated privileges.

Review carefully before installing. Prefer manual, version-pinned downloads with published checksums or signatures; avoid running curl | bash or irm | iex from a mutable branch, especially in an Administrator shell. Protect or rotate any API keys stored under ~/.fastclaw, and treat rm -rf ~/.fastclaw as permanent deletion of local FastClaw data.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
README.md:50
Finding

Mutable Remote Installation Scripts Are Executed Without Review or Verification

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
scripts/install.sh:45
Finding

Downloaded Native Binary Is Installed Without Cryptographic Integrity Verification

Content
View full analysis
Remediation
View remediation

T02 · Agent Memory Poisoning

Warning
Location
templates/SOUL.md:84
Finding

Agent Template Encourages Unbounded Persistent Storage of Conversation-Derived Context

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (32)

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

Piping network content directly into bash is a classic chaining hazard because it removes the user's chance to inspect the script before execution. In an installation guide, this pattern strongly increases the likelihood of widespread compromise if the upstream script is altered maliciously or accidentally.

Content

Scanner excerpt · README.md (reported line 85)May include surrounding context.

方式一:终端一键安装

bash
curl -fsSL https://raw.githubusercontent.com/fastclaw-ai/fastclaw/main/install.sh | bash

方式二:手动安装

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Even though the path is scoped to the application's data directory, rm -rf ~/.fastclaw is an irreversible recursive delete command. In documentation for end users, copy-paste destructive commands without safeguards can cause accidental loss of configuration, memory, and stored secrets.

Content

Scanner excerpt · README.md (reported line 234)May include surrounding context.

bash
# 停止 FastClaw 后执行
rm -rf ~/.fastclaw

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Even though the path is scoped to the application's data directory, rm -rf ~/.fastclaw is an irreversible recursive delete command. In documentation for end users, copy-paste destructive commands without safeguards can cause accidental loss of configuration, memory, and stored secrets.

Content

Scanner excerpt · README.md (reported line 234)May include surrounding context.

bash
# 停止 FastClaw 后执行
rm -rf ~/.fastclaw

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · README.md (reported line 254)May include surrounding context.

md
pkill fastclaw

# 删除程序
sudo rm /usr/local/bin/fastclaw

# (可选)删除用户数据
rm -rf ~/.fastclaw

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

This command recursively deletes the application's user data directory during uninstall and may remove secrets and state irreversibly. While legitimate as an optional cleanup action, it should be treated as dangerous because users may not realize the full extent of data loss.

Content

Scanner excerpt · README.md (reported line 257)May include surrounding context.

sudo rm /usr/local/bin/fastclaw

(可选)删除用户数据

rm -rf ~/.fastclaw

text

---

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

This command recursively deletes the application's user data directory during uninstall and may remove secrets and state irreversibly. While legitimate as an optional cleanup action, it should be treated as dangerous because users may not realize the full extent of data loss.

Content

Scanner excerpt · README.md (reported line 257)May include surrounding context.

sudo rm /usr/local/bin/fastclaw

(可选)删除用户数据

rm -rf ~/.fastclaw

text

---

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The same chaining pattern is used for updates, so a future repository compromise could turn routine upgrades into arbitrary code execution across existing installs. Because the URL points to a mutable branch path, users implicitly trust whatever content exists at update time.

Content

Scanner excerpt · README.md (reported line 268)May include surrounding context.

bash
# macOS/Linux
curl -fsSL https://raw.githubusercontent.com/fastclaw-ai/fastclaw/main/install.sh | bash

# Windows - 重新下载最新版本即可

Chaining Abuse

High
Category
Tool Misuse
Confidence
96% confidence
Finding

The documented use of 'curl ... | bash' is a classic chaining pattern that turns network content directly into executed shell commands. In a deployment skill, this is especially dangerous because users may follow the documented one-liner without review, making any compromise of the upstream repository or account an instant code-execution event.

Content

Scanner excerpt · scripts/install.sh (reported line 4)May include surrounding context.

sh
#!/bin/bash
# FastClaw macOS/Linux 一键安装脚本
# 运行方式:
# curl -fsSL https://raw.githubusercontent.com/fastclaw-ai/fastclaw/main/install.sh | bash

set -e

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/install.sh (reported line 51)May include surrounding context.

sh
# 解压
echo "[2/3] Extracting..."
tar -xzf "${INSTALL_DIR}/fastclaw.tar.gz" -C "${INSTALL_DIR}"
rm "${INSTALL_DIR}/fastclaw.tar.gz"

# 安装到 PATH
if [[ "$OSTYPE" == "darwin"* ]]; then

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README instructs users to run a PowerShell one-liner that downloads and immediately executes a remote script via iex. This creates a direct remote-code-execution path if the upstream script, GitHub account, repository, or transport context is compromised, and the risk is amplified because the instructions recommend running it as Administrator.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The macOS/Linux install command pipes a fetched network script directly into bash, which executes unreviewed remote code immediately. If the hosting repo or distribution path is tampered with, users could execute arbitrary commands on their systems without any verification step.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 105)May include surrounding context.

bash
# macOS
tar -xzf fastclaw_darwin_arm64.tar.gz
sudo mv fastclaw /usr/local/bin/

# Linux
tar -xzf fastclaw_linux_amd64.tar.gz

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 109)May include surrounding context.

bash
# macOS
tar -xzf fastclaw_darwin_arm64.tar.gz
sudo mv fastclaw /usr/local/bin/

# Linux
tar -xzf fastclaw_linux_amd64.tar.gz

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The documentation tells users to enter API keys and reveals that credentials are stored under ~/.fastclaw/apikeys.json, but it does not warn that these are sensitive secrets or discuss local file-permission and backup exposure risks. On shared systems or poorly secured environments, this can lead to credential disclosure and downstream account abuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README provides rm -rf ~/.fastclaw as a cleanup step without a strong warning that it irreversibly deletes all local FastClaw data. Users may lose agent state, configuration, memories, and stored credentials if they copy-paste the command without understanding its effects.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The uninstall instructions include sudo rm and rm -rf commands but do not clearly warn about irreversible deletion or the risks of elevated privileges. This increases the chance of destructive user error and normalizes copy-pasting privileged shell commands from documentation.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
78% confidence
Finding

sudo rm /usr/local/bin/fastclaw is a privileged destructive command. While uninstalling a known binary is legitimate, presenting elevated deletion commands without strong cautions can lead to harmful copy-paste behavior and makes mistakes under root privileges more dangerous.

Content

Scanner excerpt · README.md (reported line 254)May include surrounding context.

md
pkill fastclaw

# 删除程序
sudo rm /usr/local/bin/fastclaw

# (可选)删除用户数据
rm -rf ~/.fastclaw

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
72% confidence
Finding

The skill advertises installation and deployment behavior and static analysis detected shell capability, but the manifest does not declare any explicit tool scope such as permissions or allowed-tools. That creates an authorization gap where an agent or platform may permit broader command execution than users expect, increasing the risk of unintended system changes during deployment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs users to configure third-party LLM API keys and routes them to external providers, but provides no warning about secret handling, data sharing, retention, or trust boundaries. Users may enter sensitive credentials and prompts into services they do not fully understand, which can lead to credential exposure or confidential data disclosure to external vendors.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

On first-time installation, the script immediately creates directories, downloads an archive, extracts it, and may move a binary into a common PATH location without an explicit confirmation step. While typical for bootstrap installers, this reduces informed consent and increases the chance a user runs impactful filesystem changes they did not fully expect, especially when paired with a curl-to-shell usage pattern.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The installer downloads a release archive from the network and installs a binary into a user-controlled directory and potentially into /usr/local/bin, but it does so without any integrity verification such as a checksum or signature check. In the context of an installer, downloading and installing software is expected behavior, but the lack of authenticity verification means a compromised release channel, mirror, or build pipeline could deliver a trojaned binary.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/install.sh (reported line 61)May include surrounding context.

sh
echo ""
        echo "Note: /usr/local/bin is not writable."
        echo "Add '${INSTALL_DIR}' to your PATH, or run:"
        echo "  sudo mv ${INSTALL_DIR}/fastclaw /usr/local/bin/fastclaw"
    fi
else
    if [[ -w "/usr/local/bin" ]]; then

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/install.sh (reported line 70)May include surrounding context.

sh
echo ""
        echo "Note: /usr/local/bin is not writable."
        echo "Add '${INSTALL_DIR}' to your PATH, or run:"
        echo "  sudo mv ${INSTALL_DIR}/fastclaw /usr/local/bin/fastclaw"
    fi
else
    if [[ -w "/usr/local/bin" ]]; then

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
71% confidence
Finding

SQP-3 applies to natural-language policy issues in all file types, including markdown templates. The entire template defines the agent persona and workflow only in Chinese and includes no indication that language should be user-selected or that the locale restriction is intentional for a region-specific use case.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The template instructs the agent to modify MEMORY.md based on conversation content, which moves beyond passive persona/configuration into persistent state mutation. In a skill template, this can cause unexpected data retention or file writes without explicit user awareness or consent, increasing privacy and integrity risk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.