External Script Fetching
- Category
- Supply Chain
- Confidence
- 96% confidence
- Finding
The skill instructs the agent to install software by piping a remotely fetched script directly into a shell (
curl ... | bash). This is dangerous because it executes unverified code from the network with the user's privileges, and if the endpoint, transport, hosting, or supply chain is compromised, arbitrary code execution can occur immediately. In this skill context, the risk is elevated because the content is an operational runbook for an agent, making automated or semi-automated execution of the unsafe install path more likely.- Content
-
oo: command not found— install the oo CLI (other platforms: https://cli.oomol.com/install-guide.md):bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell
-
