{"data":{"skill":{"slug":"halt-catch-fire-product-hunt-launch","name":"product-hunt-launch","icon":"📦","repo":"https://github.com/halt-catch-fire/skills/tree/main/guides/product/product-hunt-launch/","status":"approved","author":"halt-catch-fire","authorVersion":null,"skillstoreRevision":1},"audit":{"id":"cb1bd75a-827b-4275-87f7-7b4522af9fda","skill_id":"d792d506-21db-4b5a-a3ff-4756132098dd","version":3,"content_hash":"v3:a06681402992ceae98ba04d54cfd4ab004862696:030fdb35cfa915180ba550eea73c28cc607f75d57d83e65cbeaf0e486ab9211a:78825be7e9cf5a2d502e020210d67db454cf725cab150eeed9d4205c7776f795:736b696c6c732f68616c742d63617463682d666972652f70726f647563742d68756e742d6c61756e6368:6ffbc4b200e5fd481bcbf9384c75f1f7","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"The skill is a Markdown Product Hunt launch guide with visible belt CLI examples and documentation links. The static findings are Markdown backticks, fenced examples, ordinary links, and launch-planning wording rather than hidden execution, malware behavior, prompt injection, or data exfiltration.","remediation":[],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":7,"line_start":7},{"file":"SKILL.md","line_end":15,"line_start":15},{"file":"SKILL.md","line_end":31,"line_start":17},{"file":"SKILL.md","line_end":68,"line_start":31},{"file":"SKILL.md","line_end":95,"line_start":68},{"file":"SKILL.md","line_end":113,"line_start":95},{"file":"SKILL.md","line_end":121,"line_start":113},{"file":"SKILL.md","line_end":147,"line_start":121},{"file":"SKILL.md","line_end":159,"line_start":147},{"file":"SKILL.md","line_end":163,"line_start":159},{"file":"SKILL.md","line_end":178,"line_start":163},{"file":"SKILL.md","line_end":214,"line_start":178},{"file":"SKILL.md","line_end":229,"line_start":214},{"file":"SKILL.md","line_end":255,"line_start":229},{"file":"SKILL.md","line_end":259,"line_start":255},{"file":"SKILL.md","line_end":261,"line_start":259}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":11,"line_start":11},{"file":"SKILL.md","line_end":15,"line_start":15}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":1,"total_lines":263,"audit_model":"codex","audited_at":"2026-07-06T16:52:43.866+00:00","created_at":"2026-07-17T17:01:30.86031+00:00","static_findings":[{"id":"external_commands:SKILL.md:7:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> **Install the belt CLI skill:** `npx skills add belt-sh/cli`","category":"external_commands","line_end":7,"severity":"medium","line_start":7},{"id":"external_commands:SKILL.md:15:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> Requires inference.sh CLI (`belt`). [Install instructions](https://raw.githubusercontent.com/infer","category":"external_commands","line_end":15,"severity":"medium","line_start":15},{"id":"external_commands:SKILL.md:17:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":31,"severity":"medium","line_start":17},{"id":"external_commands:SKILL.md:31:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":68,"severity":"medium","line_start":31},{"id":"external_commands:SKILL.md:68:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":95,"severity":"medium","line_start":68},{"id":"external_commands:SKILL.md:95:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":113,"severity":"medium","line_start":95},{"id":"external_commands:SKILL.md:113:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":121,"severity":"medium","line_start":113},{"id":"external_commands:SKILL.md:121:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":147,"severity":"medium","line_start":121},{"id":"external_commands:SKILL.md:147:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":159,"severity":"medium","line_start":147},{"id":"external_commands:SKILL.md:159:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":163,"severity":"medium","line_start":159},{"id":"external_commands:SKILL.md:163:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":178,"severity":"medium","line_start":163},{"id":"external_commands:SKILL.md:178:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":214,"severity":"medium","line_start":178},{"id":"external_commands:SKILL.md:214:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":229,"severity":"medium","line_start":214},{"id":"external_commands:SKILL.md:229:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":255,"severity":"medium","line_start":229},{"id":"external_commands:SKILL.md:255:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":259,"severity":"medium","line_start":255},{"id":"external_commands:SKILL.md:259:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":261,"severity":"medium","line_start":259},{"id":"network:SKILL.md:11:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"Optimize your Product Hunt launch with research and visuals via [inference.sh](https://inference.sh)","category":"network","line_end":11,"severity":"low","line_start":11},{"id":"network:SKILL.md:15:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"> Requires inference.sh CLI (`belt`). [Install instructions](https://raw.githubusercontent.com/infer","category":"network","line_end":15,"severity":"low","line_start":15},{"id":"blocker:SKILL.md:78:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"\"prompt\": \"product feature showcase, split screen showing drag-and-drop interface on left and genera","category":"blocker","line_end":78,"severity":"low","line_start":78},{"id":"blocker:SKILL.md:131:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"| Avoid | Weekends, holidays, major Apple/Google events |","category":"blocker","line_end":131,"severity":"low","line_start":131}],"finding_verdicts":[{"id":"external_commands:SKILL.md:7:ruby-shell-backtick-execution","reason":"The detected backticks wrap an inline Markdown install command, not Ruby or shell backtick execution inside executable code. It is visible documentation and is not automatically evaluated by the skill file.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:15:ruby-shell-backtick-execution","reason":"The backticks only format the CLI name in a prerequisite note. The line links to install instructions and does not execute a command or interpolate user input.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:17:ruby-shell-backtick-execution","reason":"This is the opening of a fenced bash example showing belt usage for login, image generation, and search. It is documentation text, not hidden execution logic in the skill.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:31:ruby-shell-backtick-execution","reason":"This is the closing fence for the Quick Start command example. A Markdown fence delimiter is not executable code and creates no command injection path.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:68:ruby-shell-backtick-execution","reason":"This opens a fenced bash example for optional gallery image generation commands. The commands are presented openly for user review and are not run by the Markdown file itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:95:ruby-shell-backtick-execution","reason":"This is only a Markdown code fence boundary after example belt commands. It does not invoke a shell or evaluate attacker-controlled data.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:113:ruby-shell-backtick-execution","reason":"This fenced block contains tagline examples, not shell syntax. The backticks are Markdown formatting and have no execution semantics.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:121:ruby-shell-backtick-execution","reason":"This is the closing delimiter for non-executable tagline text examples. It is a documentation artifact rather than command execution.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:147:ruby-shell-backtick-execution","reason":"This fenced block contains a maker comment template for copywriting. It does not contain shell commands or executable instructions.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:159:ruby-shell-backtick-execution","reason":"This is the closing delimiter for the maker comment template. Markdown backticks here do not create a runtime execution path.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:163:ruby-shell-backtick-execution","reason":"This fenced block contains sample launch comment prose. It is non-executable text and does not process user input as code.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:178:ruby-shell-backtick-execution","reason":"This is the closing delimiter for a prose example. No shell interpreter or Ruby backtick execution is involved.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:214:ruby-shell-backtick-execution","reason":"This opens a fenced bash example for research commands using belt apps. The commands are visible examples and are not automatically executed by the skill file.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:229:ruby-shell-backtick-execution","reason":"This is the closing fence for documented research commands. The delimiter itself is not executable and does not hide command behavior.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:255:ruby-shell-backtick-execution","reason":"This opens a fenced bash block listing related skill installation commands. The commands are explicit documentation, not covert execution logic.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:259:ruby-shell-backtick-execution","reason":"This is the closing delimiter for related skill examples. It is Markdown syntax and cannot execute shell commands.","verdict":"false_positive","confidence":0.91},{"id":"network:SKILL.md:11:hardcoded-url","reason":"The URL is a plain documentation link to inference.sh, the service named by the skill. It is not used in code to transmit data or contact an endpoint automatically.","verdict":"false_positive","confidence":0.93},{"id":"network:SKILL.md:15:hardcoded-url","reason":"The URL points to public install instructions in GitHub raw content. It is disclosed documentation, not a hidden callback or exfiltration endpoint.","verdict":"false_positive","confidence":0.93},{"id":"blocker:SKILL.md:78:system-reconnaissance","reason":"The phrase appears inside an image prompt describing a split-screen product feature showcase. It does not instruct system discovery or host reconnaissance.","verdict":"false_positive","confidence":0.93},{"id":"blocker:SKILL.md:131:system-reconnaissance","reason":"The line advises avoiding major Apple or Google events when scheduling a launch. This is marketing calendar guidance, not reconnaissance of the local system.","verdict":"false_positive","confidence":0.93}],"semantic_findings":[],"subject_marketplace_commit_sha":"a06681402992ceae98ba04d54cfd4ab004862696","subject_content_hash":"030fdb35cfa915180ba550eea73c28cc607f75d57d83e65cbeaf0e486ab9211a","subject_tree_hash":"78825be7e9cf5a2d502e020210d67db454cf725cab150eeed9d4205c7776f795","subject_plugin_path":"skills/halt-catch-fire/product-hunt-launch","audit_payload_hash":"6ffbc4b200e5fd481bcbf9384c75f1f7","confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":"a06681402992ceae98ba04d54cfd4ab004862696","contentHash":"030fdb35cfa915180ba550eea73c28cc607f75d57d83e65cbeaf0e486ab9211a","treeHash":"78825be7e9cf5a2d502e020210d67db454cf725cab150eeed9d4205c7776f795","pluginPath":"skills/halt-catch-fire/product-hunt-launch","auditPayloadHash":"6ffbc4b200e5fd481bcbf9384c75f1f7"},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":true}}