External Script Fetching
- Category
- Supply Chain
- Confidence
- 97% confidence
- Finding
The skill recommends piping a remotely fetched installer script directly into the shell. Even with a stated checksum verification step inside the installer, this pattern executes network-delivered code before the user can independently inspect it, creating a supply-chain and remote code execution risk if the distribution path, hosting, TLS trust, or installer logic is compromised.
- Content
md | Target | Command | |---|---| | macOS / Linux (interactive) | `brew install runapi-ai/tap/runapi` | | Server / CI (headless) | `curl -fsSL https://runapi.ai/cli/install.sh \| sh` | The installer detects OS and architecture (Linux and macOS, amd64 and arm64), verifies a SHA-256 checksum from `https://runapi.ai/cli/latest.json`, and refuses to write the binary if verification fails.
