Missing User Warnings
Medium
- Confidence
- 97% confidence
- Finding
- The skill instructs users to install the CLI by piping a remotely fetched script directly into bash, which executes unreviewed code from the network with the user's privileges. In an AI-agent context this is especially risky because the instruction is presented as a normal setup step, increasing the chance of non-interactive or insufficiently reviewed execution.
