External Script Fetching
- Category
- Supply Chain
- Confidence
- 97% confidence
- Finding
The skill instructs the agent to install software by piping a remotely fetched script directly into a shell (
curl ... | bash). This creates a supply-chain and remote-code-execution risk: if the host, network path, or script is compromised, arbitrary code would run immediately on the agent's system. In this skill context, that is more dangerous because the tool is intended to manage cloud infrastructure, so a compromised environment could lead to credential theft, command execution, or manipulation of DigitalOcean resources.- Content
-
oo: command not found— install the oo CLI (other platforms: https://cli.oomol.com/install-guide.md):bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell
-
