External Script Fetching
- Category
- Supply Chain
- Confidence
- 99% confidence
- Finding
The skill recommends piping a remotely fetched shell script directly into
sh, which executes unverified code from the network immediately. If the remote host, transport, DNS, CDN, or upstream script is compromised, users can suffer arbitrary code execution on their development machines or CI runners.- Content
md mkdir -p cmd/myapp internal migrations # 3. Install golangci-lint as a binary, not as a module tool (see note below) curl -sSfL https://golangci-lint.run/install.sh | sh -s -- -b $(go env GOPATH)/bin v2.14.0 # 4. Track the rest in go.mod (Go 1.24+ tool directive). Pin versions - never @latest, # which recompiles the tool on every CI run and drifts between machines.
