External Script Fetching
- Category
- Supply Chain
- Confidence
- 98% confidence
- Finding
The skill instructs users to install the CLI by piping a remotely fetched script directly into the shell (
curl ... | bash). This is dangerous because any compromise of the hosting domain, transport chain, or script contents would result in immediate arbitrary code execution on the user's machine, and the skill context makes it more risky because it explicitly presents the command as a normal recovery step during setup.- Content
-
oo: command not found— install the oo CLI (other platforms: https://cli.oomol.com/install-guide.md):bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell
-
