product-hunt-launch

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The stated purpose mostly matches the capabilities, but the skill’s real footprint is broader than a simple Product Hunt guide: it requires a remote CLI, routes user data through external services, uses wildcard Bash access, and instructs transitive installation of other skills. The install path appears official rather than overtly malicious, so this is not confirmed malware, but it carries meaningful supply-chain and trust-chain risk.

Confidence: 84%Severity: 61%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:28 PM
Package URL
pkg:socket/skills-sh/inference-sh%2Fagent-skills%2Fproduct-hunt-launch%2F@5bf9c888393edbf63782a363814567e1aad368ae