External Script Fetching
- Category
- Supply Chain
- Confidence
- 96% confidence
- Finding
The skill instructs the agent to install software by piping a remotely fetched script directly into a shell, which is a well-known unsafe pattern. If the remote host, transport, or distribution path is compromised, arbitrary code would execute immediately on the user's machine with the user's privileges; because this appears in a setup section for command recovery, an agent may be more likely to run it automatically after an error.
- Content
-
oo: command not found— install the oo CLI (other platforms: https://cli.oomol.com/install-guide.md):bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell
-
