Tooling installer security
Checksum verification, safe extraction, signing status and secret handling.
SHA-256 verification
Installers refuse to continue when the archive hash does not match the manifest. Never edit a checksum file to force an install.
Safe extraction
- Archive entries containing .. or absolute paths are rejected
- Only the expected binary is installed
- No administrator rights are required or requested
Signing status
Preview builds are not yet Authenticode-signed or notarized, so Windows SmartScreen or macOS Gatekeeper may warn. Public releases will be signed.
Secrets
The CLI and MCP server never store or return your App Secret. Keep it on your own server and issue short-lived tokens to apps.
Source references
scripts/install-fahswe-rtc.ps1tools/fahswe-rtc/internal/security
Was this page helpful?