Listen.

Normally, I'm reasonable. If something's install is curl url | bash, I know that it's not super secure, but neither is adding a random ppa to blindly install you know? I try to give the benefit of the doubt, and always read the install script without piping it directly into bash.

But ClawdBot being an AI agent with full computer access, then immediately being revealed to open ports with no auth needed? Then their official install method being curl url | bash? That shit is poetic.

This has gotta be like christmas for everyone who wags their finger at the curl url | bash install method.

ClawdBot website screenshot, showing that the official install method is to curl a bash script and pipe it straight into bash
0

If you have a fediverse account, you can quote this note from your own instance. Search https://haunted.computer/users/Dio9sys/statuses/115963578548601925 on your instance and quote it. (Note that quoting is not supported in Mastodon.)