product-hunt-launch
Pass
Audited by Gen Agent Trust Hub on Aug 12, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the
belt-sh/clivianpxand references installation resources from a GitHub repository (inference-sh/skills).- [COMMAND_EXECUTION]: The skill uses thebeltCLI (authorized through theBashtool) to run remote applications for generating marketing content and performing market research.- [PROMPT_INJECTION]: The skill ingests untrusted data from external sources via search tools, representing an attack surface for indirect prompt injection. - Ingestion points: Data enters the agent context through the outputs of
tavily/search-assistantandexa/searchtools. - Boundary markers: No explicit delimiters or instructions to ignore embedded commands are present in the snippets.
- Capability inventory: The skill has the ability to execute shell commands via the
beltCLI. - Sanitization: No evidence of data sanitization is provided.
Audit Metadata