skills/inferen-sh/skills/infsh-cli/Gen Agent Trust Hub

infsh-cli

Fail

Audited by Gen Agent Trust Hub on Mar 12, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The installation instructions recommend piping a script from https://cli.inference.sh directly into the shell (sh). This allows for the execution of arbitrary code from a remote source during the setup process.
  • [DATA_EXFILTRATION]: The infsh tool is designed to read local files (such as images, audio, and video) and upload them to the inference.sh cloud service for processing. This grants the tool access to the local filesystem for its primary AI application functionality.
  • [COMMAND_EXECUTION]: The skill requires access to the Bash shell to execute the infsh utility, perform installations, and manage updates.
Recommendations
  • HIGH: Downloads and executes remote code from: https://cli.inference.sh - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Mar 12, 2026, 09:53 PM