External Script Fetching
- Category
- Supply Chain
- Confidence
- 97% confidence
- Finding
The skill instructs the agent/user to install software by piping a remotely fetched script directly into a shell (
curl ... | bash). This creates a remote-code-execution path with no integrity verification, pinning, or manual review, so a compromised host, MITM, or malicious update to the installer would execute arbitrary code on the machine. In this skill context, the command appears in a fallback setup flow, which makes it especially risky because an automated agent may follow it when normal execution fails.- Content
-
oo: command not found— install the oo CLI (other platforms: https://cli.oomol.com/install-guide.md):bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell
-
