producthunt

Warn

Audited by Socket on Mar 11, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill presents a coherent feature set for automating Product Hunt interactions, but its install mechanism via a remote curl|bash script from an unverified domain introduces notable supply-chain risks. Credential handling is present but described as local-only with two authentication options; this is acceptable in scope but warrants caution. Data flows involve sensitive session data and credentials used to perform authenticated actions, which is consistent with the purpose but should be restricted to trusted and verifiable sources. Overall, the footprint is suspicious due to the unverifiable installer, and we should treat it as a higher-risk (suspicious) skill until a verifiable, signed install mechanism or official registry distribution is provided.

Confidence: 72%Severity: 59%
Audit Metadata
Analyzed At
Mar 11, 2026, 08:51 PM
Package URL
pkg:socket/skills-sh/manojbajaj95%2Fclaude-gtm-plugin%2Fproducthunt%2F@1038bf8119ed4fbc7a9118034aa4bfcc23b3da05