landing-page-design
Fail
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill provides installation instructions that use a highly risky pattern:
curl -fsSL https://cli.inference.sh | sh. This command downloads a script from a remote server and pipes it directly into the shell for execution, bypassing local verification and potentially allowing for arbitrary code execution if the source is compromised. - [INDIRECT_PROMPT_INJECTION]: The skill includes instructions to use search tools that ingest untrusted data from the web, creating a vulnerability to indirect prompt injection.
- Ingestion points: External data is ingested from the web via search tools in
SKILL.md(e.g.,tavily/search-assistantandexa/answer). - Boundary markers: The skill does not employ any boundary markers, delimiters, or explicit instructions to ignore embedded commands within the search results.
- Capability inventory: The agent has access to the
infshCLI which can perform network operations, execute search queries, and generate images. - Sanitization: There is no evidence of sanitization, filtering, or validation of the data returned from the search APIs before it is processed by the agent.
- [EXTERNAL_DOWNLOADS]: The skill attempts to install external dependencies using
npx skills add inference-sh/skills@.... These packages are hosted on external registries and represent unverified third-party dependencies.
Recommendations
- HIGH: Downloads and executes remote code from: https://cli.inference.sh - DO NOT USE without thorough review
- AI detected serious security threats
Audit Metadata