Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The documentation recommends piping a remotely fetched installer directly into the shell, which executes network-delivered code without prior review or integrity verification. If the upstream repository, branch reference, transport path, or hosting account were compromised, users could run arbitrary code on their systems immediately.
