landing-page-design
Fail
Audited by Gen Agent Trust Hub on Mar 29, 2026
Risk Level: CRITICALREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill instructs the user to run
curl -fsSL https://cli.inference.sh | sh. This is a highly dangerous pattern that downloads a script from an external, non-trusted source and executes it immediately with the user's current shell privileges. - [EXTERNAL_DOWNLOADS]: The skill downloads binaries from
dist.inference.shduring the installation process, and it also fetches various AI models and tool configurations from theinference.shplatform at runtime. - [COMMAND_EXECUTION]: The skill makes extensive use of a custom CLI tool (
infsh) to execute commands for image generation, web searching, and application management. These commands are configured to run within a Bash environment as specified in theallowed-toolsmetadata. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through its use of web-research tools.
- Ingestion points: Untrusted data enters the agent context via the output of
infsh app run tavily/search-assistantandinfsh app run exa/answeras seen inSKILL.md. - Boundary markers: None are present to distinguish between internal instructions and external data retrieved from search results.
- Capability inventory: The skill has shell execution capabilities restricted to the
infshcommand set. - Sanitization: There is no evidence of sanitization or filtering of the content retrieved from external URLs before it is processed by the agent.
Recommendations
- HIGH: Downloads and executes remote code from: https://cli.inference.sh - DO NOT USE without thorough review
- AI detected serious security threats
Audit Metadata