product-hunt-launch
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill uses search tools such as
tavily/search-assistantandexa/searchto research competitor launches and community sentiment. Because these tools ingest content from the open web, the retrieved data could contain instructions intended to influence the agent's behavior.\n - Ingestion points: Search queries performed via
belt app runfortavily/search-assistantandexa/searchinSKILL.md.\n - Boundary markers: No delimiters or specific safety warnings are provided for the search results.\n
- Capability inventory: Access to the
beltCLI tool for running external apps and searches.\n - Sanitization: No explicit sanitization of the search output is described.\n- [EXTERNAL_DOWNLOADS]: The skill provides instructions for installing a CLI and references external content from a GitHub repository for setup.\n
- Source:
https://raw.githubusercontent.com/inference-sh/skills/refs/heads/main/cli-install.md.
Audit Metadata