External Script Fetching
- Category
- Supply Chain
- Confidence
- 95% confidence
- Finding
The skill instructs use of a remote-install pattern that pipes a network-fetched script directly into a shell (
curl ... | bash). If an agent follows this guidance, it could execute unverified code from an external source, enabling supply-chain compromise or arbitrary code execution on the host.- Content
-
oo: command not found— install the oo CLI (other platforms: https://cli.oomol.com/install-guide.md):bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell
-
