ai-product-photography

Warn

Audited by Gen Agent Trust Hub on Mar 12, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill requires the Bash tool with a wildcard permission for the infsh CLI (infsh *). While intended for interacting with the vendor's image generation service, this broad permission allows the agent to execute any subcommand of the CLI, which increases the potential attack surface.
  • [EXTERNAL_DOWNLOADS]: The documentation suggests installing additional skills using npx skills add inference-sh/skills. The use of the name inference-sh (with 'ce') contradicts the declared author context inferen-sh. Per the security guidelines, this mismatch between the author name and the source organization for external dependencies may indicate a typosquatting risk or an unverifiable remote source.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 12, 2026, 10:01 PM