External Script Fetching
- Category
- Supply Chain
- Confidence
- 97% confidence
- Finding
The skill instructs the agent to install software by piping a remotely fetched script directly into the shell (
curl ... | bash). This is dangerous because any compromise of the remote host, CDN, TLS interception point, or installer path could result in arbitrary code execution on the user's machine, and the skill context makes it more risky because it presents this as an operational fallback during normal task execution.- Content
-
oo: command not found— install the oo CLI (other platforms: https://cli.oomol.com/install-guide.md):bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell
-
