product-hunt-launch
Audited by Socket on Mar 7, 2026
1 alert found:
Obfuscated FileThe skill's stated purpose (Product Hunt launch optimization) is broadly aligned with its capabilities (gallery image generation, competitor research, launch-day planning) but it relies heavily on external, unverifiable CLIs and remote services to perform core tasks. This creates non-trivial supply-chain and data-flow risks, particularly around data transmitted to external image-generation and research services. There is no explicit credential harvesting or exploitation, but the pattern of downloading/running external binaries and sending prompts to third-party services warrants caution. Overall, the footprint is suspicious rather than clearly benign, primarily due to external tool invocation and data flows to non-authoritative endpoints without explicit in-skill verification or sandboxing.