mine-reddit-android-pain-points

Pass

Audited by Gen Agent Trust Hub on Aug 5, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process data from external Reddit threads. This creates a surface for indirect prompt injection, where user-generated content on Reddit could contain instructions intended to manipulate the agent's analysis or output.
  • Ingestion points: Data retrieved from subreddits such as r/Android and r/AndroidApps via search, API, or third-party tools (Pushshift/Apify).
  • Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded commands within the fetched Reddit data.
  • Capability inventory: The skill mentions using the Reddit API, custom scripts, and external services like Apify to gather data.
  • Sanitization: There are no requirements listed for sanitizing or filtering the content retrieved from external sources before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 5, 2026, 11:17 PM
Security Audit — agent-trust-hub — mine-reddit-android-pain-points