pitch-deck-visuals

Fail

Audited by Gen Agent Trust Hub on Mar 29, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill recommends installing the infsh CLI via curl -fsSL https://cli.inference.sh | sh. This pattern downloads a script from a remote server and executes it directly in the shell, posing a significant risk of arbitrary code execution.\n- [EXTERNAL_DOWNLOADS]: The skill downloads setup scripts from https://cli.inference.sh and suggests adding other external skills using npx skills add, which involves fetching and executing packages from external registries.\n- [COMMAND_EXECUTION]: The skill uses the infsh command-line tool to execute logic. It includes examples of running dynamically generated Python code via infsh/python-executor and rendering HTML via infsh/html-to-image, which involves passing code strings to a remote execution environment.
Recommendations
  • HIGH: Downloads and executes remote code from: https://cli.inference.sh - DO NOT USE without thorough review
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Mar 29, 2026, 02:05 AM
Security Audit — agent-trust-hub — pitch-deck-visuals