External Script Fetching
- Category
- Supply Chain
- Confidence
- 98% confidence
- Finding
The skill instructs users to install software via a remote script piped directly into a shell, which executes code fetched at runtime without verification. If the remote host, transport, or install script is compromised, this becomes arbitrary code execution on the user's machine; the fact that this appears inside a tool skill makes it more dangerous because an agent may reproduce or recommend the command during troubleshooting.
- Content
-
oo: command not found— install the oo CLI (other platforms: https://cli.oomol.com/install-guide.md):bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell
-
