product-hunt-launch

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill uses search tools such as tavily/search-assistant and exa/search to research competitor launches and community sentiment. Because these tools ingest content from the open web, the retrieved data could contain instructions intended to influence the agent's behavior.\n
  • Ingestion points: Search queries performed via belt app run for tavily/search-assistant and exa/search in SKILL.md.\n
  • Boundary markers: No delimiters or specific safety warnings are provided for the search results.\n
  • Capability inventory: Access to the belt CLI tool for running external apps and searches.\n
  • Sanitization: No explicit sanitization of the search output is described.\n- [EXTERNAL_DOWNLOADS]: The skill provides instructions for installing a CLI and references external content from a GitHub repository for setup.\n
  • Source: https://raw.githubusercontent.com/inference-sh/skills/refs/heads/main/cli-install.md.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 02:21 PM
Security Audit — agent-trust-hub — product-hunt-launch