External Script Fetching
- Category
- Supply Chain
- Confidence
- 96% confidence
- Finding
The skill instructs the agent to install software by piping a remote script directly into a shell (
curl ... | bash). This bypasses integrity verification, makes the executed code dependent on the current contents of a third-party URL, and creates a supply-chain/RCE risk if the host, transport, or distribution pipeline is compromised. In this skill context, the danger is elevated because the content explicitly tells an automation agent when to run the command during fallback setup, which could lead to unattended execution.- Content
-
oo: command not found— install the oo CLI (other platforms: https://cli.oomol.com/install-guide.md):bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell
-
