Back to skill

Security audit

Product Hunt Launch Tracker

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly does what it says, but its URL handling can send requests to unintended hosts and its advertised Telegram alert feature is not implemented.

Install only if you are comfortable with a manual Node.js tool that makes outbound web requests. Use only known-good https://www.producthunt.com/posts/... URLs, and treat the Telegram alert claim as inaccurate unless the publisher updates the implementation. The publisher should add strict URL parsing, hostname allowlisting, redirect handling, and explicit network permission metadata before broad use.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
track-upvotes.js:22
Finding

Server-Side Request Forgery Through Insufficient Product Hunt URL Validation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The core tracking purpose mostly matches: the code does retrieve Product Hunt upvotes, comments, and rank, and it can compare current upvotes to the previous check. However, the description materially overstates behavior by promising Telegram alerts when rank improves. The code contains no Telegram integration, no outbound messaging, no scheduled trigger, and no alerting logic tied to leaderboard movement. Instead, it provides local fetch/scrape functions and a CLI for manual invocation, with ephemeral in-memory history only for the current process. So the declared description does not accurately represent the implemented capabilities.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
85% confidence
Finding

The skill advertises functionality that reads public Product Hunt pages directly, which implies network access, but the manifest declares no explicit tool scope or permissions. This creates a transparency and policy gap: consumers or hosting platforms may approve the skill without understanding it can make outbound requests, weakening sandboxing and trust controls.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.