External Script Fetching
- Category
- Supply Chain
- Confidence
- 97% confidence
- Finding
The skill instructs the agent to install software using a remote script piped directly into a shell (
curl ... | bash), which is a classic unsafe pattern because it executes unreviewed code fetched at runtime. Even though framed as first-time setup, embedding this command in a skill increases the likelihood that an agent may suggest or run it automatically after an error, creating a supply-chain and arbitrary code execution risk.- Content
-
oo: command not found— install the oo CLI (other platforms: https://cli.oomol.com/install-guide.md):bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell
-
