reddit-sf-community
Fail
Audited by Snyk on Jun 17, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E004: Prompt injection detected in skill instructions.
- Potential prompt injection detected (high risk: 1.00). The prompt includes explicit, deceptive operational instructions outside drafting (e.g., advising use of different networks/VPNs and separate IPs to hide multiple accounts and evade Reddit detection), which encourages covert behavior unrelated to its stated purpose as a drafting assistant.
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). This repository contains explicit, deliberate guidance and tooling to generate undetectable, persona-driven Reddit comments, plus multi-account and network-evasion instructions (VPN/warm‑up cadence) and programmatic Reddit tools — a clear design for deceptive astroturfing and policy-evasion rather than benign drafting assistance.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.95). The required runtime workflow ingests the operator-provided “Thread text” (which is outsider-authored Reddit content from other users) into the agent’s LLM context to generate the draft reply.
Issues (3)
E004
CRITICALPrompt injection detected in skill instructions.
E006
CRITICALMalicious code pattern detected in skill scripts.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata