producthunt

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill follows secure practices by using environment variables for API token management instead of hardcoding credentials.
  • [EXTERNAL_DOWNLOADS]: The skill performs network requests to the official Product Hunt GraphQL API (api.producthunt.com).
  • [INDIRECT_PROMPT_INJECTION]: The skill retrieves and displays external content from Product Hunt, which introduces a surface for indirect prompt injection.
  • Ingestion points: External data is ingested in scripts/get_post.py, scripts/get_post_comments.py, scripts/get_posts.py, scripts/get_topics.py, scripts/get_user.py, and scripts/get_user_posts.py.
  • Boundary markers: Absent. External content is printed to standard output without delimiters or instructions to treat the data as untrusted.
  • Capability inventory: The skill scripts (including scripts/producthunt_api.py) are limited to read-only GraphQL POST requests. No subprocess calls, exec/eval, or file-write operations exist in any script.
  • Sanitization: Absent. Content is truncated to specific lengths but not filtered for prompt injection payloads.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 03:42 PM
Security Audit — agent-trust-hub — producthunt