newsletter-curation
Pass
Audited by Gen Agent Trust Hub on Mar 25, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill provides an installation command that fetches a script from
https://cli.inference.shand pipes it to the shell. This is the documented method for installing the vendor's own CLI utility and includes built-in SHA-256 checksum verification to ensure file integrity. - [COMMAND_EXECUTION]: Utilizes the
infshCLI to perform content searches, generate images for newsletter headers, and manage social media distribution. These operations are scoped within theallowed-toolsconfiguration specified in the skill metadata. - [EXTERNAL_DOWNLOADS]: Recommends the installation of auxiliary skills from the vendor's GitHub organization using the
npx skills addcommand to extend functionality for design and SEO.
Audit Metadata