product-hunt-launch

Fail

Audited by Socket on Mar 4, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This skill is documentation for optimizing Product Hunt launches and uses the inference.sh CLI to generate images and run searches. The content itself is not malicious, but it contains multiple supply-chain and credential-handling risks: the explicit curl|sh install instruction (download-and-execute), reliance on hosted binaries, use of a managed CLI that collects credentials (infsh login), invocation of third-party apps that receive prompts/files, and guidance to install transitive skills via npx. These patterns are legitimate for a managed CLI workflow but are high-value supply-chain vectors and warrant caution. Users should avoid piping remote scripts directly into a shell, verify checksums out-of-band, audit the CLI and any transitive skills before installation, and avoid sending sensitive files or credentials to third-party apps unless the service and its data handling are trusted.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 4, 2026, 12:32 PM
Package URL
pkg:socket/skills-sh/tul-sh%2Fskills%2Fproduct-hunt-launch%2F@6d75bbd92f43eb31cead0e6beb6b03f33296deaa