External Script Fetching
- Category
- Supply Chain
- Confidence
- 98% confidence
- Finding
The skill recommends installing software by piping a remotely fetched script directly into a shell (
curl ... | bash), which is a classic supply-chain and remote-code-execution risk. If the remote host, network path, or installer is compromised, arbitrary code would execute immediately on the user's system with the current user's privileges.- Content
-
oo: command not found— install the oo CLI (other platforms: https://cli.oomol.com/install-guide.md):bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell
-
