Skills agent-tools
๐Ÿ“ฆ

agent-tools

Content revision r2 Critical ๐ŸŒ Network access๐Ÿ”‘ Env variables๐Ÿ“ Filesystem accessโš™๏ธ External commands

Run AI Apps with the inference.sh CLI

Running many hosted AI models often requires separate commands and input formats. This skill organizes discovery, authentication, file uploads, task tracking, and app execution through one CLI workflow.

Supports: Claude Codex Code(CC)
โš ๏ธ 38 Poor

Install with my Agent

Copy this request to your Agent. It includes the canonical Skill page and manifest.

Agent request
Review the Skillstore skill "agent-tools" from https://skillstore.io/skills/skillssh-agent-tools.md and its manifest at https://skillstore.io/api/skills/skillssh-agent-tools/manifest. Verify the artifact. Do not auto-install. Inspect the skill and report your findings, then wait for an operator or manual installation decision.

Your Agent should still show its plan and request any confirmation required by the security policy.

Agent-readable resources

Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.

Test it

Using "agent-tools". I need to turn a local product image into a short video.

Expected outcome:

A workflow that selects an image-to-video app, passes the local image path, submits the job, and checks the task result.

Using "agent-tools". How can I find a hosted model for technical research?

Expected outcome:

A discovery workflow that searches the app store, filters by category, inspects app details, and compares input requirements.

Using "agent-tools". I need a repeatable image generation test.

Expected outcome:

  • Choose a specific app version.
  • Create a sample input and edit the prompt.
  • Run the task and record the returned result.

Security Audit

Critical
v5 โ€ข 9/7/2026 Open versioned report

The skill is primarily operational documentation for a hosted AI CLI, and most findings are safe documentation patterns. The installer pipes a remote script to a shell, reads API credentials, and uses remote manifest data in command substitution, so those findings remain confirmed; social-media posting also creates a separate business-logic risk.

5
Files scanned
599
Lines analyzed
4
Review items
0
False positives ignored

Confirmed security concerns (5)

Critical
Pipe to shell pattern
curl -fsSL https://cli.inference.sh | sh
The command downloads a remote installer and executes it immediately through a shell. This creates a supply-chain and arbitrary-code-execution risk if the endpoint or connection is compromised.
Critical
Pipe to shell pattern
curl -fsSL https://cli.inference.sh | sh
The command downloads a remote installer and executes it immediately through a shell. This creates a supply-chain and arbitrary-code-execution risk if the endpoint or connection is compromised.
Critical
Pipe to shell pattern
curl -fsSL https://cli.inference.sh | sh
The command downloads a remote installer and executes it immediately through a shell. This creates a supply-chain and arbitrary-code-execution risk if the endpoint or connection is compromised.
Critical
Pipe to shell pattern
curl -fsSL https://cli.inference.sh | sh
The command downloads a remote installer and executes it immediately through a shell. This creates a supply-chain and arbitrary-code-execution risk if the endpoint or connection is compromised.
High
High-Impact Social-Media Automation
The skill demonstrates posting to Twitter through a hosted app. A mistaken prompt or compromised app could publish content using the user's account without an approval step.
The file explicitly shows a command that posts a supplied message to Twitter. This is a direct external side effect and a business-logic risk beyond generic command execution.
Capability review items (4)

These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.

High
Generic API/secret keys
export INFSH_API_KEY=your-api-key
The documentation instructs users to place an API key in an environment variable. This is a legitimate authentication mechanism, but mishandling the variable can expose a credential, so the security risk is confirmed.
High
Generic API/secret keys
| "API key invalid" | Check `INFSH_API_KEY` or re-login |
The documentation instructs users to place an API key in an environment variable. This is a legitimate authentication mechanism, but mishandling the variable can expose a credential, so the security risk is confirmed.
High
Generic API/secret keys
| `INFSH_API_KEY` | API key (overrides config) |
The documentation instructs users to place an API key in an environment variable. This is a legitimate authentication mechanism, but mishandling the variable can expose a credential, so the security risk is confirmed.
High
Shell command substitution
> curl -LO $(curl -fsSL https://dist.inference.sh/cli/manifest.json | grep -o '"url":"[^"]*"' | grep
The manual install command parses a remote manifest inside command substitution and uses the result in a download command. This creates a supply-chain risk because remote metadata influences the artifact URL.

Detected Patterns

Pipe to shell patternร—4
Audited by: claude View Audit History โ†’
Share & cite this report

Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.

Open versioned report
Security Assessment

Copy report link

https://skillstore.io/skills/skillssh-agent-tools/audits/5?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdown badge

[![Skillstore security assessment](https://skillstore.io/badges/skills/skillssh-agent-tools/security.svg)](https://skillstore.io/skills/skillssh-agent-tools?utm_source=security_passport_badge)

HTML badge

<a href="https://skillstore.io/skills/skillssh-agent-tools?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/skillssh-agent-tools/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Embed card

<iframe src="https://skillstore.io/embed/skills/skillssh-agent-tools.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Academic citations (APA ยท BibTeX ยท CFF)

APA citation

skillssh. (2026). agent-tools security audit report (audit version 5) [Author version unspecified]. Skillstore. https://skillstore.io/skills/skillssh-agent-tools/audits/5

BibTeX citation

@techreport{skillssh-skillssh-agent-tools-2026, author = {skillssh}, title = {agent-tools security audit report (audit version 5)}, institution = {Skillstore}, year = {2026}, number = {5}, url = {https://skillstore.io/skills/skillssh-agent-tools/audits/5}, note = {Author version unspecified} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "agent-tools security audit report (audit version 5)" version: "unspecified" type: report authors: - name: "skillssh" date-released: "2026-09-07" url: "https://skillstore.io/skills/skillssh-agent-tools/audits/5" identifiers: - type: other value: "skillstore:skillssh-agent-tools:audit:5" description: "Skillstore immutable audit report identifier"

Compare variants

20 installable variants

Each author remains a separate installable skill. The recommended variant is ranked by Skillstore evidence.

Why this variant is first

Higher Skillstore usage
tul-sh Recommended

tul-sh-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 60
Updated

2026-09-09

toolshell-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 57
Updated

2026-09-09

inferen-sh-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 48
Updated

2026-09-09

tool-belt-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 47
Updated

2026-09-09

inferencesh-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 45
Updated

2026-09-09

inference-sh-7-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 44
Updated

2026-09-09

inference-skills-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 43
Updated

2026-09-09

inference-sh-9-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 43
Updated

2026-09-09

qu-skills-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 42
Updated

2026-09-09

infsh-skills-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 42
Updated

2026-09-09

inf-sh-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 42
Updated

2026-09-09

inference-sh-skills-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 42
Updated

2026-09-09

inference-shell-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 42
Updated

2026-09-09

inference-sh-6-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 41
Updated

2026-09-09

inference-sh-3-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 41
Updated

2026-09-09

inference-sh-0-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 39
Updated

2026-09-09

inference-sh-8-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 38
Updated

2026-09-09

101-skills-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 38
Updated

2026-09-09

halt-catch-fire-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 37
Updated

2026-09-09

skillssh Current

skillssh-agent-tools

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 9
Updated

2026-09-09

Skillstore Score

Why this score Evidence Confidence: Medium
45
Architecture
85
Maintainability
87
Content
68
Community
91
Spec Compliance

What You Can Build

Prototype media workflows

Find image, video, audio, or 3D apps and run them with structured inputs.

Connect hosted models to projects

Use CLI commands, input files, and task tracking to test hosted models in development workflows.

Automate research tasks

Run hosted language models and search apps for repeatable research and content workflows.

Try These Prompts

Run a first app
Show me how to authenticate the inference.sh CLI and run one image-generation app with a simple prompt.
Discover the right app
Help me search the app store for a hosted video model, inspect its input schema, and choose a suitable app.
Process a local file
Create a command workflow that sends a local image to an upscaling app, saves the result, and checks the task status.
Design a reliable pipeline
Design a version-pinned inference.sh workflow for a production prototype with input validation, asynchronous tasks, retries, secret handling, and output tracking.

Best Practices

  • Inspect an app schema and generate a sample input before running it.
  • Pin app versions for repeatable tests and review hosted-app permissions.
  • Keep API keys in a protected secret manager and confirm external side effects.

Avoid

  • Do not pipe an unreviewed remote installer directly into a shell.
  • Do not upload sensitive local files to hosted apps without approval.
  • Do not automate social-media actions without previews, limits, and confirmation.

Frequently Asked Questions

What does this skill control?
It explains inference.sh CLI workflows. The hosted platform performs the actual model execution.
Do I need an account?
Yes. You need a valid inference.sh account and authentication before running hosted apps.
Can I use local files?
Yes. The documented CLI workflow accepts local paths for fields that support file or URL inputs.
Can I run long jobs asynchronously?
Yes. Submit a job without waiting, then use its task identifier to check status and retrieve results.
Does it support Claude?
The documentation includes Claude through a hosted OpenRouter application, subject to current platform availability.
Is it suitable for production automation?
It provides workflow guidance, but production use requires secret management, version pinning, validation, limits, and failure handling.

Developer Details

Author

skillssh

License

MIT

Skillstore revision

r2

Version notice

The author did not declare a version.

Ref

b1ef80115e869b66867d4eac8e3c8dc56a393a8d

Maintenance freshness

9/9/2026

Usage

8 downloads ยท 96 views

File structure

๐Ÿ“ references/

๐Ÿ“„ app-discovery.md

๐Ÿ“„ authentication.md

๐Ÿ“„ cli-reference.md

๐Ÿ“„ running-apps.md

๐Ÿ“„ SKILL.md

More from skillssh

View all
View all