External Script Fetching
- Category
- Supply Chain
- Confidence
- 96% confidence
- Finding
The skill instructs users to install the CLI by piping a remote script directly into a shell (
curl ... | bash). This is a well-known unsafe pattern because any compromise of the hosting endpoint, TLS interception, DNS hijack, or malicious script update can immediately lead to arbitrary code execution on the user's machine. In this skill context, the risk is elevated because the installation command is presented as an approved recovery step for normal operation, making users more likely to execute it without verification.- Content
-
oo: command not found— install the oo CLI (other platforms: https://cli.oomol.com/install-guide.md):bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell
-
