Back to skill

Security audit

Talking Head Production

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for AI talking-head production, but its install and optional related-skill commands create review-worthy supply-chain risk.

Review the installer before running it, prefer the manual checksum-verification path, avoid running install commands with sudo or elevated shells, and treat related-skill installs as separate trust decisions. Use only portraits and audio you have permission to upload, especially for real people's faces or voices.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:14
Finding

Unverified Remote Installer Executed Directly by a Shell

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 14
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

Vulnerable Code:

bash
curl -fsSL https://cli.inference.sh | sh && infsh login

Technical Analysis

The quick-start command downloads a mutable shell script from an external server and immediately pipes it into sh. The downloaded content is not inspected, version-pinned, or independently authenticated before execution.

HTTPS protects the connection in transit under normal conditions, but it does not guarantee that the server or its published script remains trustworthy. An attacker who compromises the hosting service, deployment pipeline, domain, or relevant TLS trust path could replace the installer with arbitrary shell commands.

The document states that the installer verifies the SHA-256 checksum of the CLI binary. This does not establish the integrity of the installer itself because the unverified script performs the verification. A malicious installer can bypass, falsify, or remove that check.

Executing remote code is not the minimum privilege necessary to install the documented CLI. The existing manual installation and checksum-verification option can provide the required functionality without directly executing a mutable network response.

Attack Path

  1. An attacker compromises cli.inference.sh, its publishing infrastructure, or another part of the delivery path.
  2. The attacker replaces the expected installer response with a malicious shell script.
  3. A user or agent follows the documented quick-start command.
  4. curl retrieves the attacker-controlled response.
  5. The pipe sends the response directly to sh without prior review or independent integrity validation.
  6. The payload executes with all permissions available to the invoking user.
  7. The payload may read accessible files and credentials, alter user configuration, downloa ...[truncated 773 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the curl | sh installation pattern from the quick-start instructions.
  2. Publish versioned CLI artifacts rather than directing users to a mutable installer endpoint.
  3. Require users to download the artifact and checksum separately, then verify integrity before execution.
  4. Pin the expected CLI version and SHA-256 digest in reviewed documentation or obtain a signed checksum manifest through an independently trusted channel.
  5. Prefer cryptographic signatures with a documented, pinned public key over checksums hosted on the same infrastructure as the binary.
  6. Ensure installation does not require administrative privileges and explicitly warn users not to run installation commands as root or through sudo.
  7. If an installer script remains available, instruct users to save and inspect it before execution rather than piping it directly into a shell.

A safer workflow would resemble:

bash
curl -fSLo infsh https://dist.inference.sh/cli/<pinned-version>/<platform>/infsh
curl -fSLo checksums.txt https://dist.inference.sh/cli/<pinned-version>/checksums.txt
grep ' infsh$' checksums.txt | sha256sum --check -
chmod 0755 infsh

The artifact version, platform path, and trusted digest or signature-verification procedure must be explicitly documented.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:201
Finding

Unpinned Related Skills Installed Through Dynamically Retrieved Tooling

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 201-203
Vulnerability Type: Insecure dependency and supply-chain usage
Risk Level: Medium

Vulnerable Code:

bash
npx skills add inference-sh/skills@ai-avatar-video
npx skills add inference-sh/skills@ai-video-generation
npx skills add inference-sh/skills@text-to-speech

Technical Analysis

The related-skill installation commands invoke tooling through npx and identify external skills using mutable names rather than reviewed, immutable versions or commit hashes. Depending on the local environment and package availability, npx may dynamically retrieve and execute package tooling. The named skill references may also resolve to content that changes after this document has been audited.

This expands the supply-chain trust boundary beyond the functionality declared by the current Skill. Users cannot reliably determine from these commands which exact tooling version and skill content will be installed.

Attack Path

  1. An attacker compromises a relevant package, registry account, source repository, release process, or mutable skill reference.
  2. The attacker publishes malicious tooling or changes the content resolved by one of the unpinned skill names.
  3. A user follows a related-skill installation command.
  4. npx resolves and potentially executes dynamically obtained package tooling.
  5. The tooling retrieves the mutable related-skill reference.
  6. Attacker-controlled package code or skill content is executed or installed in the user's environment.

Impact Assessment

The exact impact depends on the behavior and permissions of the dynamically resolved tooling. Executed package code may act with the invoking user's permissions and access files, environment variables, credentials, and network resources available to that user.

Malicious installed skill content could also influence later agent sessions when loaded. The reviewed fi ...[truncated 157 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the skills CLI package to a specific reviewed version instead of relying on dynamic resolution.
  2. Pin each related skill to an immutable release identifier or commit hash.
  3. Provide integrity hashes or signature-verification instructions for downloaded packages and skill artifacts.
  4. Use a lockfile or equivalent dependency manifest where supported.
  5. Review package lifecycle scripts and disable unnecessary install-time scripts.
  6. Treat related skills as optional dependencies and clearly disclose that they introduce separate trust boundaries.
  7. Prefer preinstalled, organization-approved tooling rather than allowing npx to retrieve executable code at invocation time.

Example pinned syntax should follow the package manager's supported immutable-version format, such as:

bash
npx --package=skills@<reviewed-version> skills add inference-sh/skills@<immutable-version-or-commit>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

curl ... | sh executes a remote script directly from the network without prior inspection, creating a classic supply-chain and remote-code-execution risk if the server, CDN, DNS, TLS termination, or publishing pipeline is compromised. The nearby note about checksum verification reduces concern somewhat, but users still execute the installer shell script itself before independently validating its contents.

Content

Scanner excerpt · SKILL.md (reported line 14)May include surrounding context.

Quick Start

bash
curl -fsSL https://cli.inference.sh | sh && infsh login

# Generate dialogue audio
infsh app run falai/dia-tts --input '{

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs users to upload portrait images and audio to third-party services for generation and lipsync, but it does not explicitly warn that these may contain biometric or voice data and may be retained or processed externally. In a media-production context, that omission can cause unintentional disclosure of sensitive personal data, especially when users process real people rather than synthetic assets.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.