Missing User Warnings
Medium
- Confidence
- 97% confidence
- Finding
- The skill instructs users to execute a remotely fetched shell script directly via `bash <(curl ...)`, which prevents meaningful inspection before execution and creates a supply-chain/RCE risk if the GitHub account, repository, branch, or network path is compromised. In a skill context, documentation that normalizes this pattern materially increases danger because users are likely to copy-paste it with their current privileges.
