Missing User Warnings
Medium
- Confidence
- 97% confidence
- Finding
- The skill instructs users to execute a remote script directly via `curl | sh`, which bypasses review of the downloaded code and gives the remote source immediate execution in the user's shell context. Even if the upstream project is legitimate, this pattern creates supply-chain risk and makes compromise of the remote endpoint or repository immediately dangerous.
