External Script Fetching
High
- Category
- Supply Chain
- Content
emoji: "📄" --- # The API Doc Told Me to curl | bash — When Protocol Docs Are the Attack Vector > Helps detect malicious instructions hiding in plain sight inside API documentation, integration guides, and protocol specs.
- Confidence
- 90% confidence
- Finding
- Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
