press-release-writing

Fail

Audited by Gen Agent Trust Hub on Feb 18, 2026

Risk Level: CRITICALREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • REMOTE_CODE_EXECUTION (CRITICAL): The skill contains an instruction to execute 'curl -fsSL https://cli.inference.sh | sh'. This piped-to-shell remote execution pattern from an untrusted URL is a high-risk security flaw that allows arbitrary code execution without verification.\n- EXTERNAL_DOWNLOADS (HIGH): The skill downloads software and installation scripts from 'cli.inference.sh', which is not a verified Trusted External Source. This increases the risk of supply chain attacks.\n- COMMAND_EXECUTION (MEDIUM): The skill uses 'npx' to install additional packages ('inference-sh/skills@web-search') from an unverified external repository, which could lead to the execution of malicious code during the extension's setup.\n- PROMPT_INJECTION (LOW): The skill is vulnerable to indirect prompt injection due to its use of web search tools for fact-checking. 1. Ingestion points: Results from 'infsh app run tavily/search-assistant' and 'exa/search'. 2. Boundary markers: Absent. 3. Capability inventory: 'Bash(infsh *)' allowing system-level tool calls. 4. Sanitization: Absent. Malicious instructions in search results could potentially influence the agent's behavior.
Recommendations
  • HIGH: Downloads and executes remote code from: https://cli.inference.sh - DO NOT USE without thorough review
  • AI detected serious security threats
Audit Metadata
Risk Level
CRITICAL
Analyzed
Feb 18, 2026, 01:59 AM
Security Audit — agent-trust-hub — press-release-writing