Back to skill

Security audit

gingiris-launch

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only launch playbook, but it includes concrete tactics for manipulating Product Hunt voting, unsolicited outreach, and reusing personal contact data without adequate consent guardrails.

Install only if you are prepared to ignore or rewrite the portions about vote pacing, cellular voting, coordinated vote solicitation, competitor-follower DMs, and importing upvoter emails. Use opt-in audiences, comply with Product Hunt and other platform rules, and collect or retain personal data only with clear consent and privacy controls.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
This guidance goes beyond ordinary launch planning by teaching users how to pace votes and vary network sources to avoid Product Hunt anti-abuse detection. That enables platform-manipulation behavior and facilitates circumvention of integrity controls, even if framed as using 'real supporters'.

Context-Inappropriate Capability

Medium
Confidence
89% confidence
Finding
Recommending direct messaging of competitor follower lists operationalizes intrusive targeting of third-party audiences without consent. This can enable harassment, spam, and misuse of scraped or inferred audience data under the cover of growth tactics.

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
The Chinese section repeats and reinforces the same targeted competitor-audience outreach tactic, increasing the likelihood of misuse across languages and audiences. Duplicating the tactic makes it part of the skill's core operating guidance rather than an incidental mention.

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The skill advises importing every upvoter email into a user pool without warning about consent, lawful basis, or platform rules. Collecting and repurposing supporter contact data in this way can create privacy violations and unauthorized marketing use.

Missing User Warnings

Medium
Confidence
81% confidence
Finding
This section promotes one-by-one DM outreach and private-community vote pulling without any privacy, anti-spam, or platform-integrity warnings. The omission matters because the surrounding content includes tactics likely to pressure users or bypass normal audience-consent boundaries.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The description omits any warning that using competitor follower lists for outreach may involve scraping, profiling, or contacting people without consent. In context, that omission increases the chance the tactic will be used as standard operating procedure.

Ssd 4

Medium
Confidence
94% confidence
Finding
The gradual, operational tone normalizes evasive ranking tactics by framing anti-abuse thresholds and detection cycles as routine launch mechanics. That materially lowers the barrier to manipulating Product Hunt ranking while appearing compliant on the surface.

Ssd 4

Medium
Confidence
87% confidence
Finding
This multi-step guidance escalates from launch planning into systematic solicitation through private groups and one-by-one DMs, which can pressure recipients and undermine platform fairness. The sequence makes abusive outreach reproducible rather than incidental.

Ssd 3

Medium
Confidence
90% confidence
Finding
Collecting and reusing upvoter email addresses as a standing user pool encourages secondary use of personal data beyond the original interaction context. Without consent and governance controls, this can violate privacy law, user expectations, and platform terms.

Ssd 3

Medium
Confidence
90% confidence
Finding
The Chinese section repeats the same data-reuse instruction, showing the privacy-risky behavior is intentional and embedded across the skill. Repetition across languages increases deployment scale and makes misuse more likely.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.