product-changelog
Pass
Audited by Gen Agent Trust Hub on Feb 25, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill provides installation instructions using 'curl -fsSL https://cli.inference.sh | sh', which downloads and executes a remote script. This resource is managed by the vendor (inference-sh-9) and is the intended method for installing their CLI tool.
- [COMMAND_EXECUTION]: The skill uses the 'infsh' command-line interface for core functionality, including user authentication and running remote applications.
- [EXTERNAL_DOWNLOADS]: The skill downloads binaries and verification checksums from the vendor's infrastructure at 'dist.inference.sh' and utilizes 'npx' to fetch related skill packages from the vendor's GitHub repository.
Audit Metadata