External Script Fetching
- Category
- Supply Chain
- Confidence
- 95% confidence
- Finding
The skill instructs users to install software by piping a remotely fetched script directly into a shell (
curl ... | bash). This bypasses integrity verification and gives the remote server or any attacker able to tamper with that response immediate code execution on the user's machine. In a skill context, this is especially risky because it is presented as an operational remediation step for auth/setup failures, increasing the chance an agent or user will run it without scrutiny.- Content
-
oo: command not found— install the oo CLI (other platforms: https://cli.oomol.com/install-guide.md):bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell
-
