External Script Fetching
- Category
- Supply Chain
- Confidence
- 98% confidence
- Finding
The skill includes a classic remote-script execution pattern: piping a downloaded script directly into bash. If the install endpoint, transport, or upstream distribution is compromised, an attacker can execute arbitrary code on the user's machine with the user's privileges; in an agent context, this is especially risky because setup instructions may be followed automatically or with limited scrutiny.
- Content
-
oo: command not found— install the oo CLI (other platforms: https://cli.oomol.com/install-guide.md):bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell
-
