Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The install step downloads an archive from the network and immediately pipes it into `tar` running as root against `/usr/local`, with no checksum or signature verification and no warning to the user. This creates a supply-chain risk: if the download source, DNS/TLS path, or hosting endpoint is compromised, a malicious tarball could overwrite files or install trojaned tooling.
