email-design
Fail
Audited by Gen Agent Trust Hub on Feb 18, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- Remote Code Execution (HIGH): The skill uses a highly dangerous pattern (
curl | sh) to execute a script from an unverified URL (https://cli.inference.sh). This allows the remote server to execute arbitrary commands on the host machine. - External Downloads (MEDIUM): The skill attempts to download and execute content from inference.sh, which is not included in the list of trusted repositories or organizations, presenting a significant supply chain risk.
Recommendations
- HIGH: Downloads and executes remote code from: https://cli.inference.sh - DO NOT USE without thorough review
- AI detected serious security threats
Audit Metadata