Analyzed Aug 8, 2026
This skill facilitates the installation and use of the belt CLI from inference.sh. It recommends a piped-to-shell installation method, which is a high-risk remote code execution pattern. Additionally, the CLI's feature of automatically uploading local files specified in input arguments presents a risk for data exfiltration if manipulated via indirect prompt injection.