Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill instructs users to install software by piping a remotely fetched script directly into a shell, without any warning or integrity verification steps. If the remote endpoint, transport path, or hosting account is compromised, this can lead to arbitrary code execution on the user's machine.
