Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

  curl -fsSL https://x.ai/cli/install.sh | bash
this is unauditable trust in XAI.


It's auditable, just redirect, don't pipe. Or fix your bash to not allow this.

It has nothing to do with XAI, other than maybe not enforcing good practice (which most devs don't follow anyway).


Or they are sending different code to different people from the same url…


Just build it


huh?

``` curl -fsSL https://x.ai/cli/install.sh | \ llm -s "Review this shell script and tell me what it does" ```

That isn't unauditable trust...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: