External Script Fetching
- Category
- Supply Chain
- Confidence
- 97% confidence
- Finding
The skill instructs the agent to install software via a remote script piped directly into bash, which is a classic supply-chain and arbitrary code execution risk. If the hosting endpoint, transport, or script contents are compromised, the user may execute attacker-controlled code on their system with no opportunity to inspect it first.
- Content
-
oo: command not found— install the oo CLI (other platforms: https://cli.oomol.com/install-guide.md):bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell
-
