producthunt
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill follows secure practices by using environment variables for API token management instead of hardcoding credentials.
- [EXTERNAL_DOWNLOADS]: The skill performs network requests to the official Product Hunt GraphQL API (api.producthunt.com).
- [INDIRECT_PROMPT_INJECTION]: The skill retrieves and displays external content from Product Hunt, which introduces a surface for indirect prompt injection.
- Ingestion points: External data is ingested in
scripts/get_post.py,scripts/get_post_comments.py,scripts/get_posts.py,scripts/get_topics.py,scripts/get_user.py, andscripts/get_user_posts.py. - Boundary markers: Absent. External content is printed to standard output without delimiters or instructions to treat the data as untrusted.
- Capability inventory: The skill scripts (including
scripts/producthunt_api.py) are limited to read-only GraphQL POST requests. No subprocess calls, exec/eval, or file-write operations exist in any script. - Sanitization: Absent. Content is truncated to specific lengths but not filtered for prompt injection payloads.
Audit Metadata