External Script Fetching
- Category
- Supply Chain
- Confidence
- 94% confidence
- Finding
The skill instructs users to install the CLI by piping a remotely fetched script directly into
bash, which is a well-known unsafe pattern because it executes unverified network content immediately. If the install endpoint, transport path, or hosting account were ever compromised, an attacker could achieve arbitrary code execution on the user's machine.- Content
-
oo: command not found— install the oo CLI (other platforms: https://cli.oomol.com/install-guide.md):bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell
-
