スキル infsh-cli
📦

infsh-cli

コンテンツリビジョン r2 重大 🌐 ネットワークアクセス🔑 環境変数📁 ファイルシステムへのアクセス⚙️ 外部コマンド

inference.sh CLIでAIアプリを実行

チームには、カスタムAPIセットアップなしでクラウドAIアプリを実行する一貫した方法が必要です。このスキルは、inference.sh CLIの発見、実行、認証、タスク追跡をガイドします。

対応: Claude Codex Code(CC)
⚠️ 38 不十分

自分のエージェントでインストール

このリクエストをエージェントにコピーしてください。正規の Skill ページとマニフェストが含まれています。

エージェントリクエスト
Review the Skillstore skill "infsh-cli" from https://skillstore.io/skills/infsh-skills-infsh-cli.md and its manifest at https://skillstore.io/api/skills/infsh-skills-infsh-cli/manifest. Verify the artifact. Do not auto-install. Inspect the skill and report your findings, then wait for an operator or manual installation decision.

エージェントは引き続き計画を提示し、セキュリティポリシーで必要な確認を求める必要があります。

エージェントが読めるリソース

AI エージェント、クローラー、スクリプトがページ全体ではなく整理されたコンテキストを必要とする場合は、これらのリンクを使ってください。

テストする

「infsh-cli」を使用しています。 製品モックアップ用の高速な画像生成アプリを見つけてください。

期待される結果:

推奨アプリ: falai/flux-2-klein-lora。次のステップ: アプリスキーマを確認し、サンプル入力を準備し、ローカルファイルのアップロードがある場合は確認します。

「infsh-cli」を使用しています。 長い動画生成ジョブを実行し、後で確認できるようにしてください。

期待される結果:

推奨フロー: 待機せずにジョブを送信し、タスクIDを記録してから、準備ができたらステータスを確認し、最終結果を保存します。

「infsh-cli」を使用しています。 クラウドアップスケーラーでローカル画像を使うのを手伝ってください。

期待される結果:

推奨フロー: 正確なファイルパスを確認し、アプリ入力スキーマを検証し、アップスケーラーを実行し、生成されたメディアURLを取得します。

セキュリティ監査

重大

Four pipe-to-shell installation instructions are confirmed critical risks, and the manual installation uses a dynamic remote download URL. Most other alerts are documentation links, placeholders, Markdown syntax, or standard configuration paths. The skill also enables local-file uploads and authenticated external actions that require explicit user control.

5
スキャンされたファイル
608
解析済み行数
2
レビュー項目
0
誤検知を無視

確認済みのセキュリティ上の懸念 (6)

重大
Pipe to shell pattern
curl -fsSL https://cli.inference.sh | sh
The command sends an unpinned remote response directly to sh. A compromised endpoint could execute arbitrary code without prior inspection.
重大
Pipe to shell pattern
curl -fsSL https://cli.inference.sh | sh
The reinstall command again executes an unpinned remote response directly in a shell. This creates the same arbitrary-code supply-chain risk.
重大
Pipe to shell pattern
curl -fsSL https://cli.inference.sh | sh
The installation command directly executes remote content through sh. Endpoint or transport compromise would provide arbitrary code execution.
重大
Pipe to shell pattern
curl -fsSL https://cli.inference.sh | sh
The primary installation path executes an unpinned remote response directly through sh. This permits arbitrary code execution if the source is compromised.
高
Automatic Local File Upload
The CLI automatically uploads supplied local paths to inference.sh. An agent could expose any readable file if a path comes from untrusted instructions.
Both files explicitly state that local paths are uploaded and provide absolute, relative, and home-directory examples.
高
Broad Authenticated External Actions
The allowed belt command scope includes public posts and app deployment. These actions can change external accounts or publish content without a built-in confirmation boundary.
The frontmatter allows every belt subcommand, while the examples document public posting and deployment operations.
機能レビュー項目 (2)

これらは、このスキルに期待される可能性のある実際のローカル機能であるため、レビューが必要ですが、確認済みの悪意ある動作としてはカウントされません。

中
Ruby/shell backtick execution
> **Install the belt CLI skill:** `npx skills add belt-sh/cli`
The line directs users to run npx and install another remote skill without a pinned version. That creates a real dependency supply-chain risk.
中
Shell command substitution
> curl -LO $(curl -fsSL https://dist.inference.sh/cli/manifest.json | grep -o '"url":"[^"]*"' | grep
The command derives a download URL from a remote manifest using fragile text parsing. Remote content controls the fetched asset location.

検出されたパターン

Pipe to shell pattern×4
監査者: codex 監査履歴を表示 →
このレポートを共有・引用

バージョン付き評価レポート、中立的なバッジ、埋め込みカード、引用を共有できます。Skillstore は証拠を報告しますが、この Skill が安全かどうかは判断しません。

バージョン別レポートを開く
セキュリティ評価

レポートリンクをコピー

https://skillstore.io/skills/infsh-skills-infsh-cli/audits/5?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdownバッジ

[![Skillstore security assessment](https://skillstore.io/badges/skills/infsh-skills-infsh-cli/security.svg)](https://skillstore.io/skills/infsh-skills-infsh-cli?utm_source=security_passport_badge)

HTMLバッジ

<a href="https://skillstore.io/skills/infsh-skills-infsh-cli?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/infsh-skills-infsh-cli/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

埋め込みカード

<iframe src="https://skillstore.io/embed/skills/infsh-skills-infsh-cli.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
学術引用 (APA · BibTeX · CFF)

APA形式の引用

infsh-skills. (2026). infsh-cli security audit report (audit version 5) [Author version unspecified]. Skillstore. https://skillstore.io/skills/infsh-skills-infsh-cli/audits/5

BibTeX形式の引用

@techreport{infsh-skills-infsh-skills-infsh-cli-2026, author = {infsh-skills}, title = {infsh-cli security audit report (audit version 5)}, institution = {Skillstore}, year = {2026}, number = {5}, url = {https://skillstore.io/skills/infsh-skills-infsh-cli/audits/5}, note = {Author version unspecified} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "infsh-cli security audit report (audit version 5)" version: "unspecified" type: report authors: - name: "infsh-skills" date-released: "2026-08-06" url: "https://skillstore.io/skills/infsh-skills-infsh-cli/audits/5" identifiers: - type: other value: "skillstore:infsh-skills-infsh-cli:audit:5" description: "Skillstore immutable audit report identifier"

バリアントを比較

インストール可能なバリアント 9 件

各作者のスキルは個別のインストール項目として維持されます。推奨バリアントは Skillstore の証拠で順位付けされます。

このバリアントが首位の理由

Skillstore での利用が多い
inferen-sh 推奨

inferen-sh-infsh-cli

Skillstore スコア 38
証拠の信頼度 中
Skillstore 利用状況 75
更新済み

2026-09-09

qu-skills-infsh-cli

Skillstore スコア 38
証拠の信頼度 中
Skillstore 利用状況 51
更新済み

2026-09-09

tool-belt-infsh-cli

Skillstore スコア 38
証拠の信頼度 中
Skillstore 利用状況 46
更新済み

2026-09-09

skillssh-infsh-cli

Skillstore スコア 38
証拠の信頼度 中
Skillstore 利用状況 41
更新済み

2026-09-09

inference-skills-infsh-cli

Skillstore スコア 38
証拠の信頼度 中
Skillstore 利用状況 41
更新済み

2026-09-09

infsh-skills-infsh-cli

Skillstore スコア 38
証拠の信頼度 中
Skillstore 利用状況 40
更新済み

2026-09-09

inference-sh-skills-infsh-cli

Skillstore スコア 38
証拠の信頼度 中
Skillstore 利用状況 40
更新済み

2026-09-09

halt-catch-fire-infsh-cli

Skillstore スコア 38
証拠の信頼度 中
Skillstore 利用状況 31
更新済み

2026-09-09

101-skills-infsh-cli

Skillstore スコア 38
証拠の信頼度 中
Skillstore 利用状況 5
更新済み

2026-09-09

Skillstore スコア

このスコアの理由 証拠の信頼度: 中
45
アーキテクチャ
85
保守性
87
コンテンツ
69
コミュニティ
83
仕様準拠

作成できるもの

メディア生成のプロトタイプ作成

単一のCLIワークフローから、画像、動画、音声、3Dアプリを見つけて実行します。

AIモデルアプリの比較

アプリカタログを検索し、スキーマを確認し、サンプル入力を作成し、再現可能なテスト実行を追跡します。

クラウドAIタスクの運用

長時間実行ジョブを送信し、タスク結果を取得し、コマンドラインセッションから出力を管理します。

これらのプロンプトを試す

アプリを見つける
infsh-cliを使用して画像生成アプリを見つけ、実行前の最も安全な次のステップを説明してください。
実行を準備する
infsh-cliを使用してfalai/flux-dev-loraのサンプル入力を作成し、実行する前に私のレビューを待ってください。
長いタスクを追跡する
infsh-cliを使用してgoogle/veo-3-1-fastを待機せずに送信し、その後ステータス確認と結果保存の方法を示してください。
ガード付きワークフローを設計する
infsh-cliを使用して、アプリ検索、スキーマレビュー、ファイルアップロード確認、選択したジョブの実行、タスクIDの記録を行うワークフローを計画してください。

ベストプラクティス

  • 本番入力で実行する前に、アプリスキーマを確認します。
  • inference.shへのアップロードを許可する前に、すべてのローカルファイルパスを確認します。
  • 再現可能な長時間実行ジョブには、バージョン固定とタスクIDを使用します。

回避

  • スクリプトを確認せずに、リモートインストーラーをシェルにパイプしないでください。
  • 承認なしに、シークレットやプライベートファイルをサードパーティアプリに渡さないでください。
  • 明示的な人間の確認なしに、Xへの投稿、フォロー、メッセージを自動化しないでください。

よくある質問

このスキルは何をするのに役立ちますか?
Claude、Codex、Claude Codeがinference.sh CLIを使用してクラウドAIアプリを見つけて実行するのを支援します。
inference.shアカウントは必要ですか?
はい。ほとんどのコマンドには、belt CLI、認証、利用可能なアカウントクォータが必要です。
Claudeモデルを実行できますか?
はい。このスキルには、Claudeやその他の言語モデル向けのOpenRouterの例が含まれています。
ローカルファイルをアップロードできますか?
はい。CLIはアプリ入力用にローカルパスをアップロードするため、使用前にすべてのパスを確認してください。
インストーラーにリスクはありませんか?
いいえ。このスキルはcurl-to-shellインストールを推奨しており、検証済みの手動手順に置き換えるべきです。
長時間実行ジョブはどのように処理されますか?
このスキルは、no-wait送信、タスクステータス確認、タスク結果の保存について説明します。

開発者情報

作成者

infsh-skills

ライセンス

MIT

Skillstore リビジョン

r2

バージョンに関する注意

作者はバージョンを宣言していません。

参照

4121de961d1b6f2ffca856260e239505c302452c

メンテナンスの新しさ

2026/8/7

利用状況

6 ダウンロード · 103 閲覧