product-hunt-launch

Pass

Audited by Gen Agent Trust Hub on Aug 12, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the belt-sh/cli via npx and references installation resources from a GitHub repository (inference-sh/skills).- [COMMAND_EXECUTION]: The skill uses the belt CLI (authorized through the Bash tool) to run remote applications for generating marketing content and performing market research.- [PROMPT_INJECTION]: The skill ingests untrusted data from external sources via search tools, representing an attack surface for indirect prompt injection.
  • Ingestion points: Data enters the agent context through the outputs of tavily/search-assistant and exa/search tools.
  • Boundary markers: No explicit delimiters or instructions to ignore embedded commands are present in the snippets.
  • Capability inventory: The skill has the ability to execute shell commands via the belt CLI.
  • Sanitization: No evidence of data sanitization is provided.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 12, 2026, 10:40 PM
Security Audit — agent-trust-hub — product-hunt-launch