スキル agent-tools
📦

agent-tools

コンテンツリビジョン r1 重大 🌐 ネットワークアクセス🔑 環境変数📁 ファイルシステムへのアクセス⚙️ 外部コマンド

エージェントからクラウド AI アプリを実行

チームには、多数のホスト型 AI モデルとメディアツールを扱うための単一のワークフローが必要です。このスキルは、発見、実行、結果追跡のために、エージェントへ構造化された inference.sh CLI ガイダンスを提供します。

対応: Claude Codex Code(CC)
⚠️ 38 不十分

自分のエージェントでインストール

このリクエストをエージェントにコピーしてください。正規の Skill ページとマニフェストが含まれています。

エージェントリクエスト
Review the Skillstore skill "agent-tools" from https://skillstore.io/skills/inference-sh-7-agent-tools.md and its manifest at https://skillstore.io/api/skills/inference-sh-7-agent-tools/manifest. Verify the artifact. Do not auto-install. Inspect the skill and report your findings, then wait for an operator or manual installation decision.

エージェントは引き続き計画を提示し、セキュリティポリシーで必要な確認を求める必要があります。

エージェントが読めるリソース

AI エージェント、クローラー、スクリプトがページ全体ではなく整理されたコンテキストを必要とする場合は、これらのリンクを使ってください。

テストする

「agent-tools」を使用しています。 製品モックアップ向けの画像生成アプリを見つけてください。

期待される結果:

  • 画像アプリのランク付き候補リスト。
  • 適合する理由を添えた推奨アプリ 1 つ。
  • 実行前のセットアップメモと承認チェックポイント。

「agent-tools」を使用しています。 プロンプトから短い動画を生成し、タスクを追跡してください。

期待される結果:

  • 選択された動画アプリと必須入力計画。
  • ジョブ実行前の確認リクエスト。
  • タスク追跡のガイダンスと結果取得手順。

「agent-tools」を使用しています。 Web 検索を使用して、あるトピックに関する最新情報を収集してください。

期待される結果:

  • 検索アプリの推奨。
  • リクエストされたトピックのクエリ計画。
  • ソース処理メモ付きの簡潔な結果要約。

セキュリティ監査

重大

Confirmed risks are concentrated in remote installer guidance that pipes downloaded content into a shell and uses dynamic command substitution. Most hardcoded URL, environment variable, filesystem, and Markdown backtick findings are documentation or legitimate CLI references. A semantic concern remains because the skill can guide public Twitter/X actions through the infsh CLI.

5
スキャンされたファイル
554
解析済み行数
7
レビュー項目
0
誤検知を無視

確認済みのセキュリティ上の懸念 (5)

重大
Pipe to shell pattern
curl -fsSL https://cli.inference.sh | sh
The command pipes a remote HTTPS response directly into a shell. A compromised endpoint, DNS path, or transport trust failure would execute attacker-controlled installer code.
重大
Pipe to shell pattern
curl -fsSL https://cli.inference.sh | sh
The reinstall command pipes a remote HTTPS response directly into a shell. This is a real remote code execution risk if the installer endpoint is compromised.
重大
Pipe to shell pattern
curl -fsSL https://cli.inference.sh | sh
The installation reference pipes downloaded script content directly into sh. That pattern can execute attacker-controlled code if the remote installer or delivery path is compromised.
重大
Pipe to shell pattern
curl -fsSL https://cli.inference.sh | sh
The skill recommends piping a remote installer directly to sh. That can execute arbitrary code if the installer endpoint or delivery path is compromised.
高
Public External Action Automation
The skill documents running inference.sh apps that post to Twitter/X, including a direct post-tweet example. These commands can publish content through a connected account and need explicit user confirmation.
The SKILL.md examples explicitly include x/post-tweet and list Twitter/X actions. This is clear side-effecting external automation, not a pattern-match duplicate.
機能レビュー項目 (7)

これらは、このスキルに期待される可能性のある実際のローカル機能であるため、レビューが必要ですが、確認済みの悪意ある動作としてはカウントされません。

中
Shell command substitution
> curl -LO $(curl -fsSL https://dist.inference.sh/cli/manifest.json | grep -o '"url":"[^"]*"' | grep
The manual install block evaluates a remote manifest through command substitution to choose a download URL. This increases install risk because the selected artifact source is hidden inside shell expansion.
中
Template literal with command substitution
> ```bash
The cited manual install block contains the dynamic command-substitution download flow. It is documentation, but users or agents may execute it during installation.
低
Hardcoded URL
curl -fsSL https://cli.inference.sh | sh
This URL is part of a remote installer command that downloads executable script content from the network. The URL itself is expected, but it supports a risky install flow and should remain visible as a low network risk.
低
Hardcoded URL
curl -fsSL https://cli.inference.sh | sh
This URL is part of a reinstall command that downloads executable script content from the network. It supports the same risky remote installer flow as the install section.
低
Hardcoded URL
curl -fsSL https://cli.inference.sh | sh
This URL is used in a remote installer command that fetches executable content from the network. It is expected for installation, but it is still part of a risky install path.
低
Hardcoded URL
curl -fsSL https://cli.inference.sh | sh
This URL is embedded in a remote installer command that fetches executable content. The URL is expected, but it supports a risky pipe-to-shell install flow.
低
Hardcoded URL
> curl -LO $(curl -fsSL https://dist.inference.sh/cli/manifest.json | grep -o '"url":"[^"]*"' | grep
This URL is used inside command substitution that fetches a manifest to select a binary download. It is a real network dependency in the install path.

検出されたパターン

Pipe to shell pattern×4
監査者: codex 監査履歴を表示 →
このレポートを共有・引用

バージョン付き評価レポート、中立的なバッジ、埋め込みカード、引用を共有できます。Skillstore は証拠を報告しますが、この Skill が安全かどうかは判断しません。

バージョン別レポートを開く
セキュリティ評価

レポートリンクをコピー

https://skillstore.io/skills/inference-sh-7-agent-tools/audits/5?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdownバッジ

[![Skillstore security assessment](https://skillstore.io/badges/skills/inference-sh-7-agent-tools/security.svg)](https://skillstore.io/skills/inference-sh-7-agent-tools?utm_source=security_passport_badge)

HTMLバッジ

<a href="https://skillstore.io/skills/inference-sh-7-agent-tools?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/inference-sh-7-agent-tools/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

埋め込みカード

<iframe src="https://skillstore.io/embed/skills/inference-sh-7-agent-tools.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
学術引用 (APA · BibTeX · CFF)

APA形式の引用

inference-sh-7. (2026). agent-tools security audit report (audit version 5) [Author version unspecified]. Skillstore. https://skillstore.io/skills/inference-sh-7-agent-tools/audits/5

BibTeX形式の引用

@techreport{inference-sh-7-inference-sh-7-agent-tools-2026, author = {inference-sh-7}, title = {agent-tools security audit report (audit version 5)}, institution = {Skillstore}, year = {2026}, number = {5}, url = {https://skillstore.io/skills/inference-sh-7-agent-tools/audits/5}, note = {Author version unspecified} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "agent-tools security audit report (audit version 5)" version: "unspecified" type: report authors: - name: "inference-sh-7" date-released: "2026-07-09" url: "https://skillstore.io/skills/inference-sh-7-agent-tools/audits/5" identifiers: - type: other value: "skillstore:inference-sh-7-agent-tools:audit:5" description: "Skillstore immutable audit report identifier"

バリアントを比較

インストール可能なバリアント 20 件

各作者のスキルは個別のインストール項目として維持されます。推奨バリアントは Skillstore の証拠で順位付けされます。

このバリアントが首位の理由

Skillstore での利用が多い
tul-sh 推奨

tul-sh-agent-tools

Skillstore スコア 38
証拠の信頼度 中
Skillstore 利用状況 59
更新済み

2026-09-09

toolshell-agent-tools

Skillstore スコア 38
証拠の信頼度 中
Skillstore 利用状況 56
更新済み

2026-09-09

inferen-sh-agent-tools

Skillstore スコア 38
証拠の信頼度 中
Skillstore 利用状況 47
更新済み

2026-09-09

tool-belt-agent-tools

Skillstore スコア 38
証拠の信頼度 中
Skillstore 利用状況 46
更新済み

2026-09-09

inferencesh-agent-tools

Skillstore スコア 38
証拠の信頼度 中
Skillstore 利用状況 44
更新済み

2026-09-09

inference-sh-9-agent-tools

Skillstore スコア 38
証拠の信頼度 中
Skillstore 利用状況 43
更新済み

2026-09-09

inference-sh-7-agent-tools

Skillstore スコア 38
証拠の信頼度 中
Skillstore 利用状況 43
更新済み

2026-09-09

inf-sh-agent-tools

Skillstore スコア 38
証拠の信頼度 中
Skillstore 利用状況 42
更新済み

2026-09-09

inference-skills-agent-tools

Skillstore スコア 38
証拠の信頼度 中
Skillstore 利用状況 42
更新済み

2026-09-09

inference-sh-skills-agent-tools

Skillstore スコア 38
証拠の信頼度 中
Skillstore 利用状況 42
更新済み

2026-09-09

inference-shell-agent-tools

Skillstore スコア 38
証拠の信頼度 中
Skillstore 利用状況 42
更新済み

2026-09-09

qu-skills-agent-tools

Skillstore スコア 38
証拠の信頼度 中
Skillstore 利用状況 41
更新済み

2026-09-09

infsh-skills-agent-tools

Skillstore スコア 38
証拠の信頼度 中
Skillstore 利用状況 41
更新済み

2026-09-09

inference-sh-6-agent-tools

Skillstore スコア 38
証拠の信頼度 中
Skillstore 利用状況 40
更新済み

2026-09-09

inference-sh-3-agent-tools

Skillstore スコア 38
証拠の信頼度 中
Skillstore 利用状況 40
更新済み

2026-09-09

inference-sh-0-agent-tools

Skillstore スコア 38
証拠の信頼度 中
Skillstore 利用状況 39
更新済み

2026-09-09

inference-sh-8-agent-tools

Skillstore スコア 38
証拠の信頼度 中
Skillstore 利用状況 38
更新済み

2026-09-09

101-skills-agent-tools

Skillstore スコア 38
証拠の信頼度 中
Skillstore 利用状況 38
更新済み

2026-09-09

halt-catch-fire-agent-tools

Skillstore スコア 38
証拠の信頼度 中
Skillstore 利用状況 36
更新済み

2026-09-09

skillssh-agent-tools

Skillstore スコア 38
証拠の信頼度 中
Skillstore 利用状況 9
更新済み

2026-09-09

Skillstore スコア

このスコアの理由 証拠の信頼度: 中
45
アーキテクチャ
85
保守性
87
コンテンツ
69
コミュニティ
83
仕様準拠

作成できるもの

AI 機能をプロトタイプする

個別の統合を構築せずに、ホスト型モデルを見つけ、スキーマを確認し、サンプル入力を生成し、試験ジョブを実行します。

メディアアセットを生成する

一貫したコマンドワークフローから、画像、動画、音声、3D 生成アプリを実行します。

検索と LLM タスクを実行する

調査、要約、回答生成、タスク追跡に検索アプリと LLM アプリを使用します。

これらのプロンプトを試す

アプリを見つける
agent-tools を使用して [task] 向けに inference.sh を検索してください。関連するアプリを比較し、1 つの選択肢を推奨してください。
シンプルなジョブを実行する
agent-tools を使用して [app] のサンプル入力を生成してください。必須フィールドを説明し、私が承認した後に実行してください。
メディアワークフローを構築する
agent-tools を使用して [asset] を生成し、タスクを追跡し、結果を保存するワークフローを作成してください。
複数アプリのパイプラインを運用する
agent-tools を使用して [pipeline] 向けの inference.sh アプリを発見、検証、実行してください。コスト、プライバシー、確認チェックポイントを含めてください。

ベストプラクティス

  • クラウドアプリを実行する前に、アカウント、コスト、データの機密性を確認します。
  • 本番タスクを送信する前に、サンプル入力を生成して確認します。
  • ソーシャルメディアやその他のアカウント変更操作の前に、明示的な承認を求めます。

回避

  • ダウンロードされた成果物を検証せずにインストーラーコマンドを実行しないでください。
  • 承認なしに、シークレット、個人データ、規制対象コンテンツをモデル入力として送信しないでください。
  • 明確なユーザーリクエストと確認なしに Twitter/X 操作を自動化しないでください。

よくある質問

このスキルはエージェントが何をするのに役立ちますか?
エージェントが inference.sh CLI を使用して、アプリの発見、入力の準備、タスクの実行、結果の取得を行うのを支援します。
inference.sh アカウントは必要ですか?
はい。ほとんどのコマンドを実行する前に、CLI がインストールされ、認証されている必要があります。
画像や動画を生成できますか?
はい。リファレンスには、画像、動画、音声、テキスト、検索、3D、ユーティリティアプリのワークフローが含まれています。
Claude または OpenRouter モデルを呼び出せますか?
はい。このスキルには、OpenRouter 経由の Claude やその他の LLM アプリプロバイダーの例が含まれています。
Twitter/X に投稿できますか?
はい、接続された inference.sh アプリとアカウントが許可している場合は可能です。ユーザーは、すべての公開操作を事前に確認する必要があります。
主な安全上の懸念は何ですか?
インストーラーコマンド、クラウドへのデータ送信、使用料金、アカウント変更を伴う自動化は、実行前に確認が必要です。

開発者情報

作成者

inference-sh-7

ライセンス

MIT

Skillstore リビジョン

r1

バージョンに関する注意

作者はバージョンを宣言していません。

参照

3e4b6c31a74a3bd1a291c98cf585d720cb9fbc88

メンテナンスの新しさ

2026/7/22

利用状況

8 ダウンロード · 140 閲覧

inference-sh-7 のその他のスキル

すべて表示
すべて表示