Missing User Warnings
Medium
- Confidence
- 97% confidence
- Finding
- The documentation instructs users to pipe a remotely fetched script directly into the shell without any integrity verification, pinning, or warning. This creates a supply-chain and remote-code-execution risk: if the remote host, transport, or script content is compromised, users will execute attacker-controlled code immediately.
