Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill instructs users to execute a remote install script directly via curl-pipe-to-shell, which bypasses normal review of the downloaded code at the moment of execution. Even though the note claims checksum verification and limited behavior, users are still being asked to trust a network-delivered script and the hosting infrastructure, creating a supply-chain and arbitrary code execution risk.
