pitch-deck-visuals

Fail

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The Quick Start section of 'SKILL.md' directs users to download and execute a script from 'https://cli.inference.sh' using 'curl | sh'. This method provides no opportunity for code verification before execution, creating a significant risk of arbitrary code execution from a third-party source.
  • [EXTERNAL_DOWNLOADS]: The skill references 'npx skills add inferencesh/skills', which facilitates the download and integration of additional instructions and tools from a remote repository. This introduces external dependencies that are not audited as part of the primary skill.
  • [DYNAMIC_EXECUTION]: The skill uses 'infsh/python-executor' to run dynamically generated Python code for creating charts. This runtime execution of generated code increases the attack surface for potential exploits.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted HTML and data labels as inputs for its rendering tools in 'SKILL.md'. This represents a surface for injection where malicious instructions embedded in processed data could attempt to influence the agent. The skill lacks explicit boundary markers or sanitization logic to isolate external content from its execution environment.
  • [COMMAND_EXECUTION]: The skill utilizes the 'infsh' command-line tool via 'Bash' to perform its core functions. Because the installation of this tool relies on an unverified remote script, any subsequent execution of its commands inherits the risk established at installation.
Recommendations
  • HIGH: Downloads and executes remote code from: https://cli.inference.sh - DO NOT USE without thorough review
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 26, 2026, 11:03 PM
Security Audit — agent-trust-hub — pitch-deck-visuals