The scanner mostly mistook Markdown formatting and model identifiers for Ruby or shell backtick execution. A remote image, mutable installation guidance, broad belt permission, and hosted processing create low-to-medium privacy and supply-chain risks. No prompt injection or malicious exfiltration intent was found.
The allowed-tools rule permits every belt subcommand, while the documented workflow needs only login, app discovery, and app execution.
The wildcard permission is explicit and broader than the commands demonstrated in the file. The impact depends on capabilities exposed by the installed belt CLI.
The skill recommends unversioned npx installations and mutable remote instructions, so later upstream changes may alter installed behavior without review.
The commands and raw repository link contain no immutable version or commit pin. This is a clear supply-chain exposure, although no malicious upstream behavior is shown.
Prompts and Image References Sent to Hosted Models
The examples submit prompts and user-supplied image URLs to hosted model applications, which may expose sensitive creative or personal data.
The app-run examples explicitly include prompts and external image URLs as inputs. Service-side retention and access controls are not described in the skill.
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
The installation link targets mutable raw content on a remote repository. Following changing installation instructions creates a limited supply-chain risk.
The scanner mostly mistook Markdown formatting and model identifiers for Ruby or shell backtick execution. A remote image, mutable installation guidance, broad belt permission, and hosted processing create low-to-medium privacy and supply-chain risks. No prompt injection or malicious exfiltration intent was found.
The allowed-tools rule permits every belt subcommand, while the documented workflow needs only login, app discovery, and app execution.
The wildcard permission is explicit and broader than the commands demonstrated in the file. The impact depends on capabilities exposed by the installed belt CLI.
The skill recommends unversioned npx installations and mutable remote instructions, so later upstream changes may alter installed behavior without review.
The commands and raw repository link contain no immutable version or commit pin. This is a clear supply-chain exposure, although no malicious upstream behavior is shown.
Prompts and Image References Sent to Hosted Models
The examples submit prompts and user-supplied image URLs to hosted model applications, which may expose sensitive creative or personal data.
The app-run examples explicitly include prompts and external image URLs as inputs. Service-side retention and access controls are not described in the skill.
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
The installation link targets mutable raw content on a remote repository. Following changing installation instructions creates a limited supply-chain risk.
The skill is documentation-only, but it authorizes and instructs use of the external belt CLI. Most static backtick findings are Markdown formatting or model IDs, while command examples and install commands are real external command guidance. No prompt injection text was found, but prompts and image inputs may be sent to third-party services.
The skill grants Bash access for any belt subcommand. A compromised or changed instruction could use belt beyond the documented image workflows.
The allowed-tools front matter explicitly permits Bash(belt *). The risk is contextual because belt behavior depends on the installed CLI and account permissions.
The documented workflows send prompts and image URLs to inference.sh hosted apps. Sensitive prompts, private image URLs, or client assets may leave the user environment.
The examples directly invoke hosted model apps and include prompt text or image URL fields. This confirms external processing, though it appears to be the intended feature rather than malicious behavior.
Capability review items (16)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
> **Install the belt CLI skill:** `npx skills add belt-sh/cli`
This is an explicit npx install command from a community skill. Following it can install another skill through an external package workflow, so it has supply-chain risk even though it is documentation.
This code block instructs users to run belt login and belt app run against a hosted image service. The command is intentional, but it executes an external CLI and sends prompt data outside the workspace.
This range includes a documented belt app store command for browsing remote apps. It is a lower-confidence command risk because the static location starts on a closing fence, but the referenced command still uses the external CLI.
This line embeds a remote image from cloud.inference.sh. Rendering the documentation may fetch third-party content and expose viewer metadata to that host.
Most Ruby backtick findings are Markdown false positives, but several examples intentionally run the belt CLI and npx installers. The skill has real external command and network exposure because prompts, image URLs, and install commands can leave the reviewed package.
The skill allows Bash(belt *), which permits any belt subcommand instead of only the image-generation commands shown in examples. This broad permission can affect account state or call remote services beyond the narrow workflow.
The allowed-tools front matter directly grants Bash access to every belt subcommand. The rest of the skill relies on belt for login, model discovery, and app execution.
The documented workflows send prompts and image URLs to inference.sh apps and model providers, but the skill does not include a privacy warning. Users may submit sensitive images or unreleased visual concepts without clear notice.
The cited examples include prompts and image_url or images fields for remote app runs. The file does not show a disclosure about third-party processing or sensitive data handling.
Capability review items (20)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
> **Install the belt CLI skill:** `npx skills add belt-sh/cli`
The skill tells users to run npx skills add belt-sh/cli, which can install community package code outside the reviewed skill. This is a real supply-chain command risk, although it is not Ruby backtick execution.
The quick start runs belt login and belt app run commands through an external CLI. These commands can authenticate an account and send prompt data to outside services.
Generate images with 50+ AI models via [inference.sh](https://inference.sh) CLI.
The hardcoded inference.sh URL identifies the external service the skill depends on. Using the skill can route prompts or images to that service, so the dependency is real.
The install instructions link points to raw GitHub content outside the reviewed package. Remote install guidance can change after review and influence setup commands.
The URL is a placeholder, but it appears inside examples that send image URLs to external belt apps. This documents a real data-sharing path when users provide images.
belt app run falai/topaz-image-upscaler --input '{"image_url": "https://..."}'
The URL is a placeholder, but it appears inside examples that send image URLs to external belt apps. This documents a real data-sharing path when users provide images.
The URL is a placeholder, but it appears inside examples that send image URLs to external belt apps. This documents a real data-sharing path when users provide images.
The skill is documentation-only, but it authorizes and instructs use of the external belt CLI. Most static backtick findings are Markdown formatting or model IDs, while command examples and install commands are real external command guidance. No prompt injection text was found, but prompts and image inputs may be sent to third-party services.
The skill grants Bash access for any belt subcommand. A compromised or changed instruction could use belt beyond the documented image workflows.
The allowed-tools front matter explicitly permits Bash(belt *). The risk is contextual because belt behavior depends on the installed CLI and account permissions.
The documented workflows send prompts and image URLs to inference.sh hosted apps. Sensitive prompts, private image URLs, or client assets may leave the user environment.
The examples directly invoke hosted model apps and include prompt text or image URL fields. This confirms external processing, though it appears to be the intended feature rather than malicious behavior.
Capability review items (16)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
> **Install the belt CLI skill:** `npx skills add belt-sh/cli`
This is an explicit npx install command from a community skill. Following it can install another skill through an external package workflow, so it has supply-chain risk even though it is documentation.
This code block instructs users to run belt login and belt app run against a hosted image service. The command is intentional, but it executes an external CLI and sends prompt data outside the workspace.
This range includes a documented belt app store command for browsing remote apps. It is a lower-confidence command risk because the static location starts on a closing fence, but the referenced command still uses the external CLI.
This line embeds a remote image from cloud.inference.sh. Rendering the documentation may fetch third-party content and expose viewer metadata to that host.