Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill instructs users to install tooling by piping remotely fetched scripts directly into the shell, without any integrity verification, pinning to a reviewed artifact, or warning about the risk. If the upstream script, hosting path, or delivery channel is compromised, users could execute arbitrary code on their machine during setup.
