External Script Fetching
- Category
- Supply Chain
- Confidence
- 98% confidence
- Finding
The skill recommends piping a remotely fetched script directly into a shell (
curl ... | bash), which is a well-known supply-chain and remote-code-execution risk. If the remote server, network path, or hosted script is compromised, an agent or user following this instruction could execute arbitrary code on the local system with the user's privileges.- Content
-
oo: command not found— install the oo CLI (other platforms: https://cli.oomol.com/install-guide.md):bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell
-
