mine-reddit-android-pain-points
Pass
Audited by Gen Agent Trust Hub on Aug 5, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process data from external Reddit threads. This creates a surface for indirect prompt injection, where user-generated content on Reddit could contain instructions intended to manipulate the agent's analysis or output.
- Ingestion points: Data retrieved from subreddits such as r/Android and r/AndroidApps via search, API, or third-party tools (Pushshift/Apify).
- Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded commands within the fetched Reddit data.
- Capability inventory: The skill mentions using the Reddit API, custom scripts, and external services like Apify to gather data.
- Sanitization: There are no requirements listed for sanitizing or filtering the content retrieved from external sources before processing.
Audit Metadata