External Script Fetching
- Category
- Supply Chain
- Confidence
- 95% confidence
- Finding
The skill instructs the agent to install software by piping a remotely fetched script directly into a shell (
curl ... | bash). This is dangerous because it executes network content without verification, integrity checking, or user review; if the hosting site, transport, or distribution path is compromised, arbitrary code will run on the user's machine. In this skill context, the risk is heightened because the install command appears as an endorsed recovery step for normal operation, making it more likely an agent or user will execute it reflexively.- Content
-
oo: command not found— install the oo CLI (other platforms: https://cli.oomol.com/install-guide.md):bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell
-
