This appears to be a real JavaScript SDK documentation skill, but it needs Review because it combines broad Node/npm command authority with unsafe copy-paste examples around credentials, uploads, public files, tool execution, and eval.
Install only if you are intentionally working with @inferencesh/sdk. Approve npm, npx, node, yarn, and pnpm commands case by case; keep real API keys server-side; do not use NEXT_PUBLIC variables for privileged keys; upload only files you intend to send to the service; avoid public: true for sensitive files; replace eval examples with a safe parser; and add allowlists, validation, and human approval around webhooks, browser automation, code execution, and model-triggered tools.