External Script Fetching
- Category
- Supply Chain
- Confidence
- 94% confidence
- Finding
The skill instructs users to install the CLI by piping a remotely fetched script directly into a shell, which executes unverified code from the network with the user's privileges. If the install endpoint, transport chain, or hosting account is compromised, this becomes an immediate remote code execution path; in a skill context, it is especially risky because the agent may surface or encourage this exact command during troubleshooting.
- Content
-
oo: command not found— install the oo CLI (other platforms: https://cli.oomol.com/install-guide.md):bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell
-
