producthunt

Fail

Audited by Socket on Mar 11, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill's stated purpose—automating Product Hunt interactions—generally aligns with browser-automation capabilities. However, the install paradigm (curl | bash from an external domain) constitutes a significant supply-chain/execution risk and elevates overall risk, warranting a Suspicious verdict. Credential handling appears standard for automation but requires careful handling to avoid exposure in logs or intermediaries. Network/data flows to Product Hunt are expected for the feature set and do not show clear exfiltration to unknown endpoints in the provided configuration. Overall assessment: SUSPICIOUS due to download-execute installation pattern and unverifiable binary risk; monitor credential handling and platform policy implications before deployment.

Confidence: 98%Severity: 75%
Audit Metadata
Analyzed At
Mar 11, 2026, 06:57 AM
Package URL
pkg:socket/skills-sh/manojbajaj95%2Fgtm-skills%2Fproducthunt%2F@1038bf8119ed4fbc7a9118034aa4bfcc23b3da05