agent-tools
Run Cloud AI Apps with belt
AI app workflows often require many separate provider tools. This skill guides Codex, Claude, and Claude Code through belt commands for discovery, execution, and task tracking.
Do not auto-install this skill.
The canonical policy requires operator review before any installation action.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "agent-tools" from https://skillstore.io/skills/qu-skills-agent-tools.md and its manifest at https://skillstore.io/api/skills/qu-skills-agent-tools/manifest. Verify the artifact. Do not auto-install. Inspect the skill and report your findings, then wait for an operator or manual installation decision.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "agent-tools". Find a cloud app for generating a product image.
Expected outcome:
The skill returns candidate image apps, summarizes each schema, and recommends the safest app to run for the requested asset.
Using "agent-tools". Run a long video generation job and check it later.
Expected outcome:
The skill submits the task, records the task identifier, and later reports the task status and available output links.
Using "agent-tools". Use a local image as input for an upscaling workflow.
Expected outcome:
The skill warns that the file will upload to a cloud app, asks for confirmation, then uses the selected file path.
Security Audit
CriticalThe audit confirms critical installer risk from multiple curl-to-shell examples and high-risk handling of local file paths that can be uploaded to cloud apps. Most API-key and documentation-link matches are false positives, but the skill still performs external CLI operations, remote app execution, and account automation. No prompt injection attempt was found in the reviewed files.
Confirmed security concerns (6)
Capability review items (19)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
๐ Network access (17)
๐ Env variables (3)
๐ Filesystem access (5)
โ๏ธ External commands (21)
Detected Patterns
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/qu-skills-agent-tools/audits/4?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/qu-skills-agent-tools?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/qu-skills-agent-tools?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/qu-skills-agent-tools/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/qu-skills-agent-tools.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA ยท BibTeX ยท CFF)
APA citation
qu-skills. (2026). agent-tools security audit report (audit version 4) [Author version unspecified]. Skillstore. https://skillstore.io/skills/qu-skills-agent-tools/audits/4BibTeX citation
@techreport{qu-skills-qu-skills-agent-tools-2026,
author = {qu-skills},
title = {agent-tools security audit report (audit version 4)},
institution = {Skillstore},
year = {2026},
number = {4},
url = {https://skillstore.io/skills/qu-skills-agent-tools/audits/4},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "agent-tools security audit report (audit version 4)"
version: "unspecified"
type: report
authors:
- name: "qu-skills"
date-released: "2026-07-05"
url: "https://skillstore.io/skills/qu-skills-agent-tools/audits/4"
identifiers:
- type: other
value: "skillstore:qu-skills-agent-tools:audit:4"
description: "Skillstore immutable audit report identifier"
Compare variants
20 installable variantsEach author remains a separate installable skill. The recommended variant is ranked by Skillstore evidence.
Why this variant is first
tul-sh-agent-tools
2026-08-21
toolshell-agent-tools
2026-08-21
inferen-sh-agent-tools
2026-08-21
tool-belt-agent-tools
2026-08-21
inferencesh-agent-tools
2026-08-21
inference-sh-skills-agent-tools
2026-08-21
inference-sh-7-agent-tools
2026-08-21
inf-sh-agent-tools
2026-08-21
inference-skills-agent-tools
2026-08-21
skillssh-agent-tools
2026-08-21
inference-sh-9-agent-tools
2026-08-21
inference-sh-3-agent-tools
2026-08-21
qu-skills-agent-tools
2026-08-21
infsh-skills-agent-tools
2026-08-21
inference-sh-6-agent-tools
2026-08-21
inference-sh-0-agent-tools
2026-08-21
inference-shell-agent-tools
2026-08-21
inference-sh-8-agent-tools
2026-08-21
101-skills-agent-tools
2026-08-21
halt-catch-fire-agent-tools
2026-08-21
Skillstore Score
Why this score Evidence Confidence: MediumWhat You Can Build
Prototype media workflows
Find and run cloud apps for images, videos, audio, and 3D assets from one CLI flow.
Compare model providers
Inspect public app schemas and run LLM, search, or generation tasks through provider-specific apps.
Track long tasks
Submit longer cloud jobs, keep task identifiers, and retrieve generated outputs when they complete.
Try These Prompts
Use agent-tools to find inference.sh apps for image generation. Show the best options and explain when to use each one.
Use agent-tools to inspect the input requirements for a video generation app and prepare a safe run plan before executing it.
Use agent-tools to run a long video task without waiting, save the task identifier, and check the result later.
Use agent-tools to design a workflow that searches for source material, generates media, and tracks every cloud task with explicit approvals.
Best Practices
- Ask for explicit approval before installing the CLI or running remote app commands.
- Confirm every local file path before upload, especially parent or home directory paths.
- Use task identifiers and app schemas to keep cloud runs reproducible.
Avoid
- Do not run the pipe-to-shell installer without verifying the source and checksum.
- Do not upload local media, audio, or documents without user confirmation.
- Do not post, follow, like, retweet, or send messages through X/Twitter without explicit consent.
Frequently Asked Questions
What does this skill help with?
Does it require an external account?
Can it upload local files?
Can it automate Twitter or X actions?
Is installation fully safe by default?
Which agent tools can use it?
Developer Details
Author
qu-skillsLicense
MIT
Skillstore revision
r1
Version notice
The author did not declare a version.
Ref
62e2a730c5cd74eab4c7164309d810de660fcea3
Maintenance freshness
7/18/2026
Usage
5 downloads ยท 0 views
File structure
๐ references/
๐ app-discovery.md
๐ authentication.md
๐ cli-reference.md
๐ running-apps.md
๐ SKILL.md