Skills agent-tools
๐Ÿ“ฆ

agent-tools

Content revision r2 Critical ๐ŸŒ Network access๐Ÿ”‘ Env variables๐Ÿ“ Filesystem accessโš™๏ธ External commands

Run Hosted AI Apps from Your Agent

Managing hosted AI models often requires different APIs and workflows. This skill uses the inference.sh belt CLI to discover, run, and track cloud AI apps.

Supports: Claude Codex Code(CC)
โš ๏ธ 38 Poor

Install with my Agent

Copy this request to your Agent. It includes the canonical Skill page and manifest.

Agent request
Review the Skillstore skill "agent-tools" from https://skillstore.io/skills/infsh-skills-agent-tools.md and its manifest at https://skillstore.io/api/skills/infsh-skills-agent-tools/manifest. Verify the artifact. Do not auto-install. Inspect the skill and report your findings, then wait for an operator or manual installation decision.

Your Agent should still show its plan and request any confirmation required by the security policy.

Agent-readable resources

Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.

Test it

Using "agent-tools". Find a fast image model for a landscape concept.

Expected outcome:

Recommended FLUX options with speed and quality notes, followed by the required prompt and image-size fields.

Using "agent-tools". Create a short video and return immediately.

Expected outcome:

The selected video app, submitted task identifier, current processing status, and the command needed to retrieve the result.

Using "agent-tools". Use my local portrait for an avatar video.

Expected outcome:

A review notice naming the local image and audio files, their hosted destination, and the final input awaiting upload confirmation.

Security Audit

Critical
v5 โ€ข 8/6/2026 Open versioned report

The skill repeatedly recommends downloading and piping an external installer into sh, creating a critical supply-chain execution risk. Its manual installation builds a download URL from a remote manifest, while local files and social actions can leave the user's environment. Most remaining detections are Markdown formatting, placeholder credential documentation, standard user directories, or expected first-party links.

5
Files scanned
599
Lines analyzed
3
Review items
0
False positives ignored

Confirmed security concerns (6)

Critical
Pipe to shell pattern
curl -fsSL https://cli.inference.sh | sh
The command downloads mutable remote content and executes it directly with sh. A compromised endpoint or delivery path would provide immediate code execution under the user's account.
Critical
Pipe to shell pattern
curl -fsSL https://cli.inference.sh | sh
The reinstall instruction again executes a remote script without giving the user an inspection or pinning step. Endpoint compromise would become local shell execution.
Critical
Pipe to shell pattern
curl -fsSL https://cli.inference.sh | sh
The installation command sends unpinned network content directly to sh. This creates a critical software supply-chain execution path.
Critical
Pipe to shell pattern
curl -fsSL https://cli.inference.sh | sh
The primary installation instructions execute downloaded remote content immediately through sh. This grants the remote endpoint code execution with the user's privileges.
Medium
Automatic Local File Uploads
Local paths supplied to supported app fields are automatically uploaded to the hosted service. Without explicit confirmation, an agent could transmit sensitive local media or documents.
Both files explicitly state that the CLI automatically uploads local files and provide absolute, relative, and home-directory path examples.
Medium
Consequential Social Media Actions
The skill can publish posts and perform other account actions through hosted X apps. It does not require a user confirmation immediately before these external side effects.
The cited lines explicitly demonstrate posting with local media and list posting, direct-message, follow, like, and retweet capabilities.
Capability review items (3)

These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.

High
Shell command substitution
> curl -LO $(curl -fsSL https://dist.inference.sh/cli/manifest.json | grep -o '"url":"[^"]*"' | grep
The command derives curl's download argument from a mutable remote manifest through shell substitution. Compromise or malformed output could redirect artifact retrieval before later installation.
Medium
Ruby/shell backtick execution
> **Install the belt CLI skill:** `npx skills add belt-sh/cli`
Although the backticks are Markdown formatting, the enclosed npx instruction executes an external package installer. Running an unpinned package introduces a supply-chain and environment-modification risk.
Low
Hardcoded URL
![[inference.sh](https://inference.sh)](https://cloud.inference.sh/app/files/u/4mg21r6ta37mpaz6ktzwt
The Markdown embeds a remote image hosted on cloud.inference.sh, which may trigger a viewer network request and disclose request metadata. Actual exposure depends on the marketplace renderer.

Detected Patterns

Pipe to shell patternร—4
Audited by: codex View Audit History โ†’
Share & cite this report

Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.

Open versioned report
Security Assessment

Copy report link

https://skillstore.io/skills/infsh-skills-agent-tools/audits/5?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdown badge

[![Skillstore security assessment](https://skillstore.io/badges/skills/infsh-skills-agent-tools/security.svg)](https://skillstore.io/skills/infsh-skills-agent-tools?utm_source=security_passport_badge)

HTML badge

<a href="https://skillstore.io/skills/infsh-skills-agent-tools?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/infsh-skills-agent-tools/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Embed card

<iframe src="https://skillstore.io/embed/skills/infsh-skills-agent-tools.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Academic citations (APA ยท BibTeX ยท CFF)

APA citation

infsh-skills. (2026). agent-tools security audit report (audit version 5) [Author version unspecified]. Skillstore. https://skillstore.io/skills/infsh-skills-agent-tools/audits/5

BibTeX citation

@techreport{infsh-skills-infsh-skills-agent-tools-2026, author = {infsh-skills}, title = {agent-tools security audit report (audit version 5)}, institution = {Skillstore}, year = {2026}, number = {5}, url = {https://skillstore.io/skills/infsh-skills-agent-tools/audits/5}, note = {Author version unspecified} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "agent-tools security audit report (audit version 5)" version: "unspecified" type: report authors: - name: "infsh-skills" date-released: "2026-08-06" url: "https://skillstore.io/skills/infsh-skills-agent-tools/audits/5" identifiers: - type: other value: "skillstore:infsh-skills-agent-tools:audit:5" description: "Skillstore immutable audit report identifier"

Compare variants

20 installable variants

Each author remains a separate installable skill. The recommended variant is ranked by Skillstore evidence.

Why this variant is first

Higher Skillstore usage
tul-sh Recommended

tul-sh-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 26
Updated

2026-08-21

toolshell-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 23
Updated

2026-08-21

inferen-sh-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 14
Updated

2026-08-21

tool-belt-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 12
Updated

2026-08-21

inferencesh-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 11
Updated

2026-08-21

inference-sh-skills-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 10
Updated

2026-08-21

inference-sh-7-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 10
Updated

2026-08-21

inf-sh-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 9
Updated

2026-08-21

inference-skills-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 9
Updated

2026-08-21

skillssh-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 8
Updated

2026-08-21

inference-sh-9-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 8
Updated

2026-08-21

inference-sh-3-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 8
Updated

2026-08-21

qu-skills-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 7
Updated

2026-08-21

infsh-skills Current

infsh-skills-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 7
Updated

2026-08-21

inference-sh-6-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 7
Updated

2026-08-21

inference-sh-0-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 7
Updated

2026-08-21

inference-shell-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 6
Updated

2026-08-21

inference-sh-8-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 5
Updated

2026-08-21

101-skills-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 5
Updated

2026-08-21

halt-catch-fire-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 4
Updated

2026-08-21

Skillstore Score

Why this score Evidence Confidence: Medium
45
Architecture
85
Maintainability
87
Content
69
Community
91
Spec Compliance

What You Can Build

Create Media Prototypes

Generate images, videos, speech, or 3D assets from prompts and inspect the returned hosted results.

Compare Hosted Models

Search available apps, inspect input schemas, and run selected language or media models with controlled inputs.

Automate Long Tasks

Submit time-consuming generation jobs, record task identifiers, and retrieve outputs after processing completes.

Try These Prompts

Find an App
Search inference.sh for apps that handle [task]. Show the best matches, categories, and required inputs. Do not run anything.
Run One App
Inspect [app name], generate a sample input, replace it with my requirements, and show the final input before running the app.
Manage an Async Task
Run [app name] without waiting using [input]. Record the task identifier, check status, and save the completed result to [destination].
Build a Reviewed Workflow
Design a workflow using inference.sh apps for [goal]. Inspect every schema, pin versions, confirm uploads and external actions, then execute approved steps.

Best Practices

  • Inspect each app schema and generate sample input before submitting custom values.
  • Pin app and installer versions when reproducible behavior matters.
  • Confirm local uploads, social actions, costs, and other external side effects before execution.

Avoid

  • Do not pipe remote installer output directly into a shell.
  • Do not pass secrets or unrelated local files as app inputs.
  • Do not publish posts, messages, or account changes without final user approval.

Frequently Asked Questions

What is required to use this skill?
You need the belt CLI, an inference.sh account, network access, and sufficient credits for the selected apps.
Which AI tasks are supported?
The documented catalog includes image, video, audio, language, search, 3D, utility, and X automation apps.
Can it use local files?
Yes. Supported local paths are automatically uploaded when an app input accepts a URL.
Can it track long-running jobs?
Yes. It can submit without waiting, retain the task identifier, and retrieve status or results later.
Does it verify generated output?
No. Review factual claims, media quality, licensing, and policy compliance before using any output.
Can it post to social media?
Yes. Some hosted X apps can post or change account state, so require explicit approval before execution.

Developer Details

License

MIT

Skillstore revision

r2

Version notice

The author did not declare a version.

Ref

4121de961d1b6f2ffca856260e239505c302452c

Maintenance freshness

8/7/2026

Usage

5 downloads ยท 112 views

File structure

๐Ÿ“ references/

๐Ÿ“„ app-discovery.md

๐Ÿ“„ authentication.md

๐Ÿ“„ cli-reference.md

๐Ÿ“„ running-apps.md

๐Ÿ“„ SKILL.md

More from infsh-skills

View all
View all