Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The README recommends installing by piping a remotely fetched script directly into a shell (`bash`/`iex`) without any integrity verification, pinning, or warning about trust implications. In an agent skill context, this is especially dangerous because an automated agent may follow installation instructions non-interactively, turning documentation into a code-execution path on the host.
