Skills agent-tools
๐Ÿ“ฆ

agent-tools

Content revision r1 Critical ๐ŸŒ Network access๐Ÿ”‘ Env variables๐Ÿ“ Filesystem accessโš™๏ธ External commands

Run Cloud AI Apps from Your Agent

Managing separate AI APIs and workflows slows production. This skill guides Claude, Codex, and Claude Code through inference.sh discovery, execution, uploads, and task tracking.

Supports: Claude Codex Code(CC)
โš ๏ธ 38 Poor

Install with my Agent

Copy this request to your Agent. It includes the canonical Skill page and manifest.

Agent request
Review the Skillstore skill "agent-tools" from https://skillstore.io/skills/101-skills-agent-tools.md and its manifest at https://skillstore.io/api/skills/101-skills-agent-tools/manifest. Verify the artifact. Do not auto-install. Inspect the skill and report your findings, then wait for an operator or manual installation decision.

Your Agent should still show its plan and request any confirmation required by the security policy.

Agent-readable resources

Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.

Test it

Using "agent-tools". Find an image generator suitable for a landscape product banner.

Expected outcome:

  • Recommended app: FLUX development model
  • Required input: a detailed image prompt
  • Optional input: landscape dimensions and image count
  • Next step: review the prepared request before execution

Using "agent-tools". Create a short video from my approved image and track it without waiting.

Expected outcome:

The selected video app accepted the image after upload confirmation. The task was submitted, tracked to completion, and its download location was reported.

Using "agent-tools". Search for recent AI platform news.

Expected outcome:

The search application returned a concise source list with titles, publication details, and links for manual review.

Security Audit

Critical
v5 โ€ข 7/12/2026 Open versioned report

The documentation contains four remote installer commands that pipe downloaded content directly into a shell, plus an unpinned package installation and a remote-data command substitution. Most other detections are Markdown examples, documentation links, placeholder credentials, or intentional user-selected paths. The skill also permits automatic cloud uploads and social account changes without requiring explicit confirmation.

5
Files scanned
599
Lines analyzed
2
Review items
0
False positives ignored

Confirmed security concerns (6)

Critical
Pipe to shell pattern
curl -fsSL https://cli.inference.sh | sh
The command downloads mutable remote content and executes it immediately in a shell. A compromised host, route, or installer can execute arbitrary code.
Critical
Pipe to shell pattern
curl -fsSL https://cli.inference.sh | sh
The reinstall command executes remote content without allowing local inspection or independent verification. Compromise of the delivery path would provide arbitrary shell execution.
Critical
Pipe to shell pattern
curl -fsSL https://cli.inference.sh | sh
The installation command directly executes a script downloaded from the network. It provides no pre-execution inspection or independently pinned integrity check.
Critical
Pipe to shell pattern
curl -fsSL https://cli.inference.sh | sh
The primary setup instructions execute an unaudited network response directly in the user's shell. A delivery compromise would permit arbitrary code execution.
High
Unconfirmed Social Account Actions
The skill exposes commands that can publish posts and identifies direct messages, follows, likes, and reposts as available actions. It provides no requirement to preview or confirm these external side effects.
The listed capabilities directly modify a connected social account, while the skill contains no confirmation or preview guardrail.
Medium
Automatic Local File Upload Without Confirmation
The skill states that local paths are automatically uploaded to cloud apps, including absolute, parent-directory, and home-directory paths. It does not require confirmation before transferring user files.
Both files explicitly document automatic uploads from local paths to cloud applications, and neither includes a confirmation requirement.
Capability review items (2)

These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.

High
Shell command substitution
> curl -LO $(curl -fsSL https://dist.inference.sh/cli/manifest.json | grep -o '"url":"[^"]*"' | grep
The shell expands a URL parsed from a mutable remote manifest and passes it to curl. The same origin supplies checksums, so compromise can redirect and validate a malicious download.
Medium
Ruby/shell backtick execution
> **Install the belt CLI skill:** `npx skills add belt-sh/cli`
The inline Markdown contains an actual npx installation command for an unpinned remote skill. Running it introduces package and skill supply-chain execution risk.

Detected Patterns

Pipe to shell patternร—4
Audited by: codex View Audit History โ†’
Share & cite this report

Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.

Open versioned report
Security Assessment

Copy report link

https://skillstore.io/skills/101-skills-agent-tools/audits/5?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdown badge

[![Skillstore security assessment](https://skillstore.io/badges/skills/101-skills-agent-tools/security.svg)](https://skillstore.io/skills/101-skills-agent-tools?utm_source=security_passport_badge)

HTML badge

<a href="https://skillstore.io/skills/101-skills-agent-tools?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/101-skills-agent-tools/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Embed card

<iframe src="https://skillstore.io/embed/skills/101-skills-agent-tools.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Academic citations (APA ยท BibTeX ยท CFF)

APA citation

101-skills. (2026). agent-tools security audit report (audit version 5) [Author version unspecified]. Skillstore. https://skillstore.io/skills/101-skills-agent-tools/audits/5

BibTeX citation

@techreport{101-skills-101-skills-agent-tools-2026, author = {101-skills}, title = {agent-tools security audit report (audit version 5)}, institution = {Skillstore}, year = {2026}, number = {5}, url = {https://skillstore.io/skills/101-skills-agent-tools/audits/5}, note = {Author version unspecified} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "agent-tools security audit report (audit version 5)" version: "unspecified" type: report authors: - name: "101-skills" date-released: "2026-07-12" url: "https://skillstore.io/skills/101-skills-agent-tools/audits/5" identifiers: - type: other value: "skillstore:101-skills-agent-tools:audit:5" description: "Skillstore immutable audit report identifier"

Compare variants

20 installable variants

Each author remains a separate installable skill. The recommended variant is ranked by Skillstore evidence.

Why this variant is first

Higher Skillstore usage
tul-sh Recommended

tul-sh-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 27
Updated

2026-08-21

toolshell-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 24
Updated

2026-08-21

inferen-sh-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 15
Updated

2026-08-21

tool-belt-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 13
Updated

2026-08-21

inferencesh-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 12
Updated

2026-08-21

inference-sh-skills-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 11
Updated

2026-08-21

inference-sh-7-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 11
Updated

2026-08-21

inf-sh-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 10
Updated

2026-08-21

inference-skills-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 10
Updated

2026-08-21

inference-sh-9-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 9
Updated

2026-08-21

inference-sh-3-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 9
Updated

2026-08-21

skillssh-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 8
Updated

2026-08-21

qu-skills-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 8
Updated

2026-08-21

infsh-skills-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 8
Updated

2026-08-21

inference-sh-0-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 8
Updated

2026-08-21

inference-sh-6-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 7
Updated

2026-08-21

inference-shell-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 6
Updated

2026-08-21

101-skills Current

101-skills-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 6
Updated

2026-08-21

inference-sh-8-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 5
Updated

2026-08-21

halt-catch-fire-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 5
Updated

2026-08-21

Skillstore Score

Why this score Evidence Confidence: Medium
45
Architecture
85
Maintainability
87
Content
65
Community
83
Spec Compliance

What You Can Build

Create Campaign Media

Generate images and videos, then monitor long-running tasks from one command workflow.

Compare AI Applications

Search the public catalog, inspect input requirements, and test suitable models.

Automate Research Collection

Run search and language applications, then save task results for later review.

Try These Prompts

Find an App
Search the inference.sh store for applications that handle [task]. Compare the most relevant options and explain their required inputs.
Run a Generation Task
Inspect [app name], prepare inputs for [desired result], show me the final request, and run it after I approve.
Use Local Media
Prepare [app name] with [local file path]. State which file will be uploaded and the destination, then wait for my confirmation.
Build a Tracked Workflow
Design a version-pinned workflow using [apps]. Validate each schema, obtain approval for external actions, submit long tasks asynchronously, and summarize their results.

Best Practices

  • Inspect each app schema and pin its version before execution.
  • Confirm every local file upload, paid request, and external account action.
  • Keep API keys in protected environment variables and exclude them from logs and prompts.

Avoid

  • Do not pipe remote installer content directly into a shell.
  • Do not upload broad directories or sensitive files to cloud applications.
  • Do not post, message, follow, like, or repost without immediate user approval.

Frequently Asked Questions

What is required to use this skill?
You need the belt CLI, an inference.sh account, and authentication through browser login or an API key.
Which AI tasks are supported?
The catalog includes image, video, language, search, audio, 3D, utility, and social applications.
Can it process local files?
Yes. The CLI can upload an explicitly selected local file after you review and approve the transfer.
Does it run long tasks?
Yes. It can submit asynchronous tasks, check their status, and save completed results.
Are model versions fixed?
Not automatically. Use the documented version syntax to pin an app release for repeatable behavior.
Can it change a social account?
Some apps can post, message, follow, like, or repost. Review the exact action and require explicit approval before execution.

Developer Details

Author

101-skills

License

MIT

Skillstore revision

r1

Version notice

The author did not declare a version.

Ref

d71c7417a35d5c2624161bd2fe8de8a41a362128

Maintenance freshness

7/18/2026

Usage

2 downloads ยท 0 views

File structure

๐Ÿ“ references/

๐Ÿ“„ app-discovery.md

๐Ÿ“„ authentication.md

๐Ÿ“„ cli-reference.md

๐Ÿ“„ running-apps.md

๐Ÿ“„ SKILL.md