product-hunt-launch

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose is plausible, but it expands into remote CLI execution, third-party hosted app routing, and transitive skill installation. The install source appears same-org and not overtly malicious, yet the mutable raw-GitHub docs, curl|sh installer, CLI-name mismatch, and platform-mediated data/auth flows make the footprint broader than a simple Product Hunt advisory skill.

Confidence: 84%Severity: 64%
Audit Metadata
Analyzed At
Apr 23, 2026, 10:14 PM
Package URL
pkg:socket/skills-sh/infsh-skills%2Fskills%2Fproduct-hunt-launch%2F@e8c8426ce77036ff51870164f1218d5490418914