Missing User Warnings
Medium
- Confidence
- 99% confidence
- Finding
- The skill tells users to execute a remote script directly via curl and process substitution, which runs downloaded code without review, pinning, or integrity verification. If the remote source, GitHub account, repository, or network path is compromised, arbitrary code will execute on the user's machine immediately.
