pitch-deck-visuals
Fail
Audited by Gen Agent Trust Hub on Mar 29, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill recommends installing the
infshCLI viacurl -fsSL https://cli.inference.sh | sh. This pattern downloads a script from a remote server and executes it directly in the shell, posing a significant risk of arbitrary code execution.\n- [EXTERNAL_DOWNLOADS]: The skill downloads setup scripts fromhttps://cli.inference.shand suggests adding other external skills usingnpx skills add, which involves fetching and executing packages from external registries.\n- [COMMAND_EXECUTION]: The skill uses theinfshcommand-line tool to execute logic. It includes examples of running dynamically generated Python code viainfsh/python-executorand rendering HTML viainfsh/html-to-image, which involves passing code strings to a remote execution environment.
Recommendations
- HIGH: Downloads and executes remote code from: https://cli.inference.sh - DO NOT USE without thorough review
- AI detected serious security threats
Audit Metadata