image-to-video
Pass
Audited by Gen Agent Trust Hub on Apr 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references a remote installation guide for the
infshCLI hosted on the vendor's GitHub repository (github.com/inference-sh/skills). - [COMMAND_EXECUTION]: The skill instructs the agent to use the
Bashtool to executeinfshcommands. Theallowed-toolsconfiguration in the frontmatter correctly restricts these operations to theinfshcommand space, implementing a principle of least privilege. - [EXTERNAL_DOWNLOADS]: The 'Related Skills' section suggests adding further capabilities using
npx skills addfrom theinference-shnamespace, which involves fetching external content from the vendor's collection.
Audit Metadata