Context-Inappropriate Capability
Medium
- Confidence
- 95% confidence
- Finding
- The install step fetches a tarball over the network with curl and immediately pipes it into tar running as root in /usr/local, with no checksum or signature verification. This creates a supply-chain execution path unrelated to the core analysis task, so a compromised download source, MITM, or tampered artifact could lead to arbitrary code installation on the host.
