External Script Fetching
- Category
- Supply Chain
- Confidence
- 90% confidence
- Finding
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
- Content
Never paste real
mb_API keys or wallet private keys into shared agent prompts, logs, or public repositories.Never pipe a remote script into a shell (
curl URL | bash). The demo is:bash npx --yes moltbillboard@0.4.0 proof
