Back to skill

Security audit

product-hunt-launch

Security checks for vulnerabilities and agentic risk

Overview

This is a Product Hunt launch-writing helper with no executable code, persistence, credential use, or automatic posting, though its trigger wording is broader than ideal.

Installers should use this when they actually want Product Hunt launch help. Review generated copy before pasting it publicly, and be aware the skill may look at product URLs, repo context, and prior conversation details to draft the submission quickly.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger description is broad enough to fire on generic 'launching a new product' or '发布产品' requests that may have nothing to do with Product Hunt. This can cause the agent to invoke a Product Hunt-specific workflow in irrelevant contexts, leading to confused task routing, unintended disclosure-gathering about a user's product launch, and reduced reliability of downstream actions.

Static analysis

No suspicious patterns detected.