External Script Fetching
- Category
- Supply Chain
- Confidence
- 98% confidence
- Finding
The skill recommends piping a remotely fetched installer script directly into a shell (
curl ... | bash), which creates a supply-chain and remote code execution risk if the hosting endpoint, transport, or script contents are compromised. Because this appears in a first-time setup path for a command-not-found condition, an agent or user following the instruction could execute unreviewed code on the local system.- Content
-
oo: command not found— install the oo CLI (other platforms: https://cli.oomol.com/install-guide.md):bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell
-
