External Script Fetching
- Category
- Supply Chain
- Confidence
- 97% confidence
- Finding
The skill instructs users to install software via a remote script piped directly into a shell (
curl ... | bash), which executes network-fetched code without prior verification. If the hosting source, transport path, or supply chain is compromised, this can result in arbitrary code execution on the user's machine; in this skill context, the danger is heightened because the command is presented as an authentication/setup fallback that users may trust and run verbatim.- Content
-
oo: command not found— install the oo CLI (other platforms: https://cli.oomol.com/install-guide.md):bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell
-
