product-hunt-launch
Pass
Audited by Gen Agent Trust Hub on Aug 28, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references the installation of the belt CLI skill using
npx skills add belt-sh/cliand points to installation instructions hosted on the officialinference-shGitHub repository. These are legitimate resources for the platform's ecosystem. - [COMMAND_EXECUTION]: The skill provides example commands using the
beltCLI, such asbelt loginandbelt app run. These commands are used to execute specific AI applications (e.g., image generation viafalai/flux-dev-loraand search viatavily/search-assistant) within theBashtool's authorized scope. - [INDIRECT_PROMPT_INJECTION]: The skill uses search applications (
tavily/search-assistant,exa/search) which ingest external data from the web. While this represents a theoretical attack surface for indirect prompt injection, the risk is minimal as the data is used for research purposes and handled by specialized search agents.
Audit Metadata