Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The documentation recommends `curl ... | sh`, which executes a remote script directly in the user's shell without an opportunity to inspect or verify its contents. If the upstream source, transport, or publishing pipeline is compromised, users could run arbitrary attacker-controlled code immediately; in an agent-oriented skill, this is more dangerous because users may follow installation steps with elevated trust and less scrutiny.
