product-photography
Pass
Audited by Gen Agent Trust Hub on Feb 25, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides a command to download an installation script from
https://cli.inference.sh, which is the official domain for the tool's vendor. - [REMOTE_CODE_EXECUTION]: The installation instructions involve piping a remote script directly into a shell (
curl | sh). While this pattern is generally high-risk, it is used here to install the vendor's own verified CLI tool. - [COMMAND_EXECUTION]: The skill defines several examples using the
Bashtool to executeinfshcommands, which send image generation requests to the vendor's infrastructure.
Audit Metadata