Back to skill

Security audit

product-hunt-launch

Security checks across malware telemetry and agentic risk

Overview

This skill is a Product Hunt launch planning guide with no code execution or automatic posting; the main caveat is that its trigger wording is broader than necessary.

Safe to install as a Product Hunt launch planning aid. Review any generated launch copy before publishing, especially if project-context files include confidential metrics, unreleased features, customer details, or private strategy.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger description is broad enough to activate on casual mentions of Product Hunt terms like "upvotes," "hunter," or "first comment," even when the user may not be asking for launch assistance. This can cause unintended skill invocation, leading to irrelevant guidance, context hijacking, or reduced reliability of the agent's routing behavior.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.