پن کیا گیا ٹویٹ

stop using curl | sh to download *any* installer you find on the internet, stop using npm to download global dependencies
this guy just built `safe`, a utility that inspects remote installer scripts before executing them, (all of this for just one star on github)
it downloads the artifact, runs static analysis, checks against vulnerability databases and reputation sources, then decides whether it's safe to run
here's an example showing Safe warning the user about the openclaw's npm install script:
github: github.com/forloopcodes/s…
English















