reddit-competitor-analysis-api-skill
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill makes network requests to
api.browseract.comto perform data extraction tasks. These operations target the official infrastructure of the skill's author (browser-act) and are consistent with the skill's primary purpose. - [COMMAND_EXECUTION]: The skill uses a Python script (
reddit_competitor_analysis_api.py) to interface with the BrowserAct API. The script is executed via theexectool with standard arguments provided by the user (keywords, sort options), following the intended usage pattern. - [INDIRECT_PROMPT_INJECTION]: The skill processes external data from Reddit search results. While this is an ingestion surface for untrusted content, the data is returned as structured strings or JSON, and the skill does not grant the agent high-privilege capabilities that would be susceptible to malicious payload execution.
- [CREDENTIALS_SAFE]: The skill manages the
BROWSERACT_API_KEYthrough environment variables. It includes explicit instructions for the agent to request the key from the user if it is missing, rather than hardcoding credentials or using insecure storage methods.
Audit Metadata