reddit-sf-community

Fail

Audited by Snyk on Jun 17, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E004: Prompt injection detected in skill instructions.

  • Potential prompt injection detected (high risk: 1.00). The prompt includes explicit, deceptive operational instructions outside drafting (e.g., advising use of different networks/VPNs and separate IPs to hide multiple accounts and evade Reddit detection), which encourages covert behavior unrelated to its stated purpose as a drafting assistant.

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). This repository contains explicit, deliberate guidance and tooling to generate undetectable, persona-driven Reddit comments, plus multi-account and network-evasion instructions (VPN/warm‑up cadence) and programmatic Reddit tools — a clear design for deceptive astroturfing and policy-evasion rather than benign drafting assistance.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.95). The required runtime workflow ingests the operator-provided “Thread text” (which is outsider-authored Reddit content from other users) into the agent’s LLM context to generate the draft reply.

Issues (3)

E004
CRITICAL

Prompt injection detected in skill instructions.

E006
CRITICAL

Malicious code pattern detected in skill scripts.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jun 17, 2026, 02:28 AM
Issues
3
Security Audit — snyk — reddit-sf-community