Skills infsh-cli
๐Ÿ“ฆ

infsh-cli

Content revision r1 Critical ๐ŸŒ Network access๐Ÿ”‘ Env variables๐Ÿ“ Filesystem accessโš™๏ธ External commands

Run Cloud AI Apps from the Command Line

Cloud AI services often require separate APIs and workflows. This skill guides Claude, Codex, and Claude Code through inference.sh app discovery and execution.

Supports: Claude Codex Code(CC)
โš ๏ธ 38 Poor

Install with my Agent

Copy this request to your Agent. It includes the canonical Skill page and manifest.

Agent request
Review the Skillstore skill "infsh-cli" from https://skillstore.io/skills/101-skills-infsh-cli.md and its manifest at https://skillstore.io/api/skills/101-skills-infsh-cli/manifest. Verify the artifact. Do not auto-install. Inspect the skill and report your findings, then wait for an operator or manual installation decision.

Your Agent should still show its plan and request any confirmation required by the security policy.

Agent-readable resources

Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.

Test it

Using "infsh-cli". Find an image generator for a product concept, but do not run it.

Expected outcome:

  • Recommended app: falai/flux-dev-lora
  • Category: image generation
  • Next step: inspect the app details and create a sample input before execution

Using "infsh-cli". Track my previously submitted video task.

Expected outcome:

The task is still running. Its identifier is preserved for the next status check, and no new task was submitted.

Using "infsh-cli". Prepare an image-upscaling request using my local photo.

Expected outcome:

The selected app accepts a local image path and an upscale factor. Confirmation is required because the photo will be uploaded to inference.sh.

Security Audit

Critical
v5 โ€ข 7/12/2026 Open versioned report

Most static alerts are false positives caused by Markdown code formatting, example paths, environment variable documentation, and expected vendor links. The pipe-to-shell installer and unquoted remote-manifest command substitution are confirmed risks. Automatic local-file uploads and social account actions also require explicit user awareness and approval.

5
Files scanned
608
Lines analyzed
1
Review items
0
False positives ignored

Confirmed security concerns (6)

Critical
Pipe to shell pattern
curl -fsSL https://cli.inference.sh | sh
The installation command executes remotely fetched content without giving the user an inspection or pinning step. A compromised endpoint could immediately run arbitrary shell commands.
Critical
Pipe to shell pattern
curl -fsSL https://cli.inference.sh | sh
The reinstall instruction again executes a mutable remote script directly in the shell. Transport security does not protect against a compromised publisher or distribution endpoint.
Critical
Pipe to shell pattern
curl -fsSL https://cli.inference.sh | sh
The documented command directly executes the response from a remote endpoint. Endpoint or supply-chain compromise would provide immediate shell execution.
Critical
Pipe to shell pattern
curl -fsSL https://cli.inference.sh | sh
The primary installation path downloads a mutable remote script and immediately executes it. A compromised service or release pipeline could run arbitrary commands in the user's account.
High
Consequential Social Account Actions Lack Confirmation Guidance
The skill can post content and advertises direct messages, follows, likes, and reposts. It does not require confirmation before these externally visible account actions.
The command example explicitly posts to Twitter, and the capability table lists other account-changing operations without an approval safeguard.
Medium
Automatic Local File Upload
Supplying a local path causes the CLI to upload that file to inference.sh automatically. Sensitive files could leave the machine without a separate upload confirmation.
Both files explicitly state that local file paths are automatically uploaded instead of treated as URLs.
Capability review items (1)

These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.

Medium
Shell command substitution
> curl -LO $(curl -fsSL https://dist.inference.sh/cli/manifest.json | grep -o '"url":"[^"]*"' | grep
The manual install command places unquoted output derived from a remote manifest into curl arguments. Malformed or compromised manifest content could alter the requested arguments despite the later checksum step.

Detected Patterns

Pipe to shell patternร—4
Audited by: codex View Audit History โ†’
Share & cite this report

Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.

Open versioned report
Security Assessment

Copy report link

https://skillstore.io/skills/101-skills-infsh-cli/audits/5?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdown badge

[![Skillstore security assessment](https://skillstore.io/badges/skills/101-skills-infsh-cli/security.svg)](https://skillstore.io/skills/101-skills-infsh-cli?utm_source=security_passport_badge)

HTML badge

<a href="https://skillstore.io/skills/101-skills-infsh-cli?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/101-skills-infsh-cli/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Embed card

<iframe src="https://skillstore.io/embed/skills/101-skills-infsh-cli.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Academic citations (APA ยท BibTeX ยท CFF)

APA citation

101-skills. (2026). infsh-cli security audit report (audit version 5) [Author version unspecified]. Skillstore. https://skillstore.io/skills/101-skills-infsh-cli/audits/5

BibTeX citation

@techreport{101-skills-101-skills-infsh-cli-2026, author = {101-skills}, title = {infsh-cli security audit report (audit version 5)}, institution = {Skillstore}, year = {2026}, number = {5}, url = {https://skillstore.io/skills/101-skills-infsh-cli/audits/5}, note = {Author version unspecified} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "infsh-cli security audit report (audit version 5)" version: "unspecified" type: report authors: - name: "101-skills" date-released: "2026-07-12" url: "https://skillstore.io/skills/101-skills-infsh-cli/audits/5" identifiers: - type: other value: "skillstore:101-skills-infsh-cli:audit:5" description: "Skillstore immutable audit report identifier"

Compare variants

9 installable variants

Each author remains a separate installable skill. The recommended variant is ranked by Skillstore evidence.

Why this variant is first

Higher Skillstore usage
inferen-sh Recommended

inferen-sh-infsh-cli

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 41
Updated

2026-08-21

qu-skills-infsh-cli

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 19
Updated

2026-08-21

tool-belt-infsh-cli

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 13
Updated

2026-08-21

skillssh-infsh-cli

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 9
Updated

2026-08-21

inference-skills-infsh-cli

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 9
Updated

2026-08-21

inference-sh-skills-infsh-cli

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 8
Updated

2026-08-21

infsh-skills-infsh-cli

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 7
Updated

2026-08-21

101-skills Current

101-skills-infsh-cli

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 5
Updated

2026-08-21

halt-catch-fire-infsh-cli

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 3
Updated

2026-08-21

Skillstore Score

Why this score Evidence Confidence: Medium
45
Architecture
85
Maintainability
87
Content
65
Community
91
Spec Compliance

What You Can Build

Create Media Prototypes

Find suitable image or video apps, inspect their inputs, and run a controlled generation task.

Test Multiple AI Models

Discover text models, generate sample inputs, compare supported options, and retrieve task results.

Automate Cloud AI Jobs

Submit long-running app tasks without waiting, then check status and save completed results.

Try These Prompts

Find an App
Search the inference.sh store for an app that can [task]. Show the best three options and explain their documented differences. Do not run anything.
Prepare a Sample Input
Inspect [app-name], describe its required inputs, and generate a sample input file. Ask before using any local file.
Run and Track a Task
Run [app-name] using [input-file] without waiting. Report the task identifier, check its status, and summarize the final result.
Compare a Controlled Model Workflow
Compare [app-one] and [app-two] for [goal]. Inspect both schemas, prepare equivalent inputs, estimate external effects, and request approval before each execution.

Best Practices

  • Inspect app details and generate a sample before each first run.
  • Pin app versions when repeatable output or stable schemas matter.
  • Confirm costs, local file uploads, and external account actions before execution.

Avoid

  • Do not pipe remote installer content directly into a shell.
  • Do not upload local files until the user confirms the exact path and destination.
  • Do not publish posts, messages, follows, likes, or reposts without immediate approval.

Frequently Asked Questions

What must be installed before using this skill?
Install the belt CLI through a verified manual method, then authenticate with an inference.sh account.
Does this skill require a GPU?
No local GPU is required because supported apps run through the inference.sh cloud service.
Can it use local images, audio, or video?
Yes. The CLI automatically uploads supported local files, so review each path and approve the transfer first.
Can it run tasks without waiting?
Yes. It can submit asynchronous tasks, retain the task identifier, and check status later.
Can it post to a social account?
Yes, when the required app and account connection exist. Every externally visible or account-changing action should require explicit confirmation.
Are model availability and prices fixed?
No. Apps, versions, schemas, quotas, and pricing are controlled by inference.sh and can change.

Developer Details

Author

101-skills

License

MIT

Skillstore revision

r1

Version notice

The author did not declare a version.

Ref

d71c7417a35d5c2624161bd2fe8de8a41a362128

Maintenance freshness

7/18/2026

Usage

1 downloads ยท 0 views

File structure

๐Ÿ“ references/

๐Ÿ“„ app-discovery.md

๐Ÿ“„ authentication.md

๐Ÿ“„ cli-reference.md

๐Ÿ“„ running-apps.md

๐Ÿ“„ SKILL.md