T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:14- Finding
Remote Installation Script Executed Directly Through a Shell
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly a technical-writing guide, but it asks users to run mutable remote installers and includes ungated public posting guidance, so it needs Review before installation.
Install only if you are comfortable using inference.sh and reviewing its installer. Prefer manual download with pinned versions and checksum or signature verification, avoid running curl-to-shell blindly, do not connect or use X posting unless you intend to publish the exact text, and treat each related skill install as a separate unpinned third-party install that should be reviewed independently.
SKILL.md:14Remote Installation Script Executed Directly Through a Shell
SKILL.md:290Unpinned Third-Party Tool and Skill Installation
curl ... | sh executes a remotely fetched script directly in the shell, creating a classic supply-chain and remote code execution risk if the server, transport, or distribution pipeline is compromised. Even with checksum claims elsewhere in the text, the one-line install pattern encourages execution before independent verification and is especially dangerous in a skill document that may be copied verbatim by users.
curl -fsSL https://cli.inference.sh | sh && infsh login
# Research topic depth
infsh app run exa/search --input '{
The manifest-style description includes many generic trigger phrases such as "technical writing," "developer content," and "technical content," which can overlap with ordinary requests and unrelated documentation tasks. It does not provide exclusion conditions or negative examples to clarify when the skill should not activate.
The skill is presented as a technical blog writing aid, but it includes an example for posting directly to X, which crosses from content drafting into external publication. That capability is materially more sensitive because it can cause unintended public disclosure, reputational damage, or unauthorized posting if invoked without explicit user confirmation.
The markdown includes an outbound X posting example without any warning that it publishes externally or that explicit approval is required. In an agent setting, silent or poorly signposted publication actions are dangerous because they can lead to accidental data release or user-harmful actions beyond drafting.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
The manifest frames the skill as technical blog post writing and writing conventions, not research or web search. While light research may support writing, explicitly invoking an external search app introduces a capability outside the declared writing-centric scope.
No suspicious patterns detected.