External Script Fetching
- Category
- Supply Chain
- Confidence
- 94% confidence
- Finding
The skill instructs the agent/user to install software by piping a remotely fetched script directly into a shell (
curl ... | bash). This creates a supply-chain and remote-code-execution risk because any compromise of the hosting domain, transport, or script contents would immediately execute arbitrary code on the target system. In this skill context, the danger is elevated because the install step is embedded as an operational fallback inside a trusted automation workflow, making unsafe execution more likely.- Content
-
oo: command not found— install the oo CLI (other platforms: https://cli.oomol.com/install-guide.md):bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell
-
