product-hunt-launch

Warn

Audited by Socket on May 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the business purpose is mostly coherent, but the skill expands its footprint by installing other skills, relying on a third-party CLI/gateway, and using a mutable raw GitHub install path with mixed publisher identities. This looks more like a dependency/provenance and transitive-trust problem than confirmed malware, but the install and execution model is broader than necessary for a Product Hunt launch guide.

Confidence: 84%Severity: 62%
Audit Metadata
Analyzed At
May 15, 2026, 07:16 PM
Package URL
pkg:socket/skills-sh/infsh-skills%2Fskills%2Fproduct-hunt-launch%2F@bf988f43585aeaeba938fb4251d0b10ae0c9de43
Security Audit — socket — product-hunt-launch