Missing User Warnings
Medium
- Confidence
- 97% confidence
- Finding
- The instructions recommend piping a remotely downloaded shell script directly into bash, which executes unverified code with no integrity check, signature verification, pinning, or review step. In a CLI-installation skill, this is especially dangerous because users are likely to copy-paste the command verbatim, so a compromised server, MITM in a misconfigured environment, or replaced artifact could lead to arbitrary code execution on the host.
