External Script Fetching
- Category
- Supply Chain
- Confidence
- 97% confidence
- Finding
The skill instructs the agent to install software by piping a remote script directly into a shell (
curl ... | bash). This is a well-known unsafe pattern because it executes unaudited code fetched at runtime, and if the distribution server, network path, or script is compromised, arbitrary code execution occurs immediately on the host. In this skill context, the danger is increased because the content is operational guidance for an agent using shell access, so the instruction is more likely to be acted on automatically whenoois missing.- Content
-
oo: command not found— install the oo CLI (other platforms: https://cli.oomol.com/install-guide.md):bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell
-
