reddit-competitor-analysis-api-skill

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill makes network requests to api.browseract.com to perform data extraction tasks. These operations target the official infrastructure of the skill's author (browser-act) and are consistent with the skill's primary purpose.
  • [COMMAND_EXECUTION]: The skill uses a Python script (reddit_competitor_analysis_api.py) to interface with the BrowserAct API. The script is executed via the exec tool with standard arguments provided by the user (keywords, sort options), following the intended usage pattern.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data from Reddit search results. While this is an ingestion surface for untrusted content, the data is returned as structured strings or JSON, and the skill does not grant the agent high-privilege capabilities that would be susceptible to malicious payload execution.
  • [CREDENTIALS_SAFE]: The skill manages the BROWSERACT_API_KEY through environment variables. It includes explicit instructions for the agent to request the key from the user if it is missing, rather than hardcoding credentials or using insecure storage methods.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 11:51 AM
Security Audit — agent-trust-hub — reddit-competitor-analysis-api-skill