product-hunt-launch

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references the installation of the belt CLI skill using npx skills add belt-sh/cli and points to installation instructions hosted on the official inference-sh GitHub repository. These are legitimate resources for the platform's ecosystem.
  • [COMMAND_EXECUTION]: The skill provides example commands using the belt CLI, such as belt login and belt app run. These commands are used to execute specific AI applications (e.g., image generation via falai/flux-dev-lora and search via tavily/search-assistant) within the Bash tool's authorized scope.
  • [INDIRECT_PROMPT_INJECTION]: The skill uses search applications (tavily/search-assistant, exa/search) which ingest external data from the web. While this represents a theoretical attack surface for indirect prompt injection, the risk is minimal as the data is used for research purposes and handled by specialized search agents.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 01:13 PM
Security Audit — agent-trust-hub — product-hunt-launch