speech-to-text
Pass
Audited by Gen Agent Trust Hub on Feb 25, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill references an installation command that fetches a shell script from
https://cli.inference.shand pipes it to the shell. This is identified as a vendor-official installation mechanism for theinfshCLI. - [COMMAND_EXECUTION]: The skill uses the Bash tool to execute
infshcommands. This is the primary function of the skill and is limited to theinfshbinary. - [EXTERNAL_DOWNLOADS]: The installation process downloads a binary from
dist.inference.shand verifies it against a SHA-256 checksum. These resources are part of the vendor's official infrastructure.
Audit Metadata