Explainer Video Guide
PassAudited by VirusTotal on May 12, 2026.
Findings (1)
The skill is classified as suspicious primarily due to the `curl -fsSL https://cli.inference.sh | sh` command found in `SKILL.md`. While this is a common method for installing CLI tools, it represents a significant supply chain vulnerability, as it executes remote code directly without prior inspection. If the `inference.sh` domain or its distribution server were compromised, this could lead to arbitrary code execution on the user's system. Although the skill's stated purpose and all other `infsh` commands appear benign and aligned with video production, this installation method introduces an unacceptable level of risk.
