reddit-post

Warn

Audited by Socket on Jul 31, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
scripts/rdtx.mjs

Overall, this module is a powerful Reddit automation CLI that uses CDP to execute code inside a real browser and can export/use authenticated cookies. While there is no clear sign of classic malware (no reverse shell/crypto-mining/exfiltration), there are meaningful security risks: (1) CDP execFile uses a configurable helper binary from environment, (2) evalInPage performs dynamic CDP eval and some eval payloads embed CLI-controlled values, creating an injection surface in the page context, and (3) it exports and stores cookie values locally (sensitive credential handling). Treat as high-privilege automation and review/lock down input sources and environment configuration.

Confidence: 65%Severity: 62%
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is coherent with its stated Reddit-posting purpose and does not show obvious credential exfiltration or third-party routing, but it grants an agent the ability to perform public account actions through a logged-in browser session via CDP. Main risk is autonomous real-world posting plus limited provenance for the local `rdtx` script, not confirmed malware.

Confidence: 84%Severity: 69%
Audit Metadata
Analyzed At
Jul 31, 2026, 01:34 PM
Package URL
pkg:socket/skills-sh/L4A-ai%2Freddit-skills%2Freddit-post%2F@4ef71748b6612799916730868b47ce550675a7ca383a9eca8df8b2f934757f02
Security Audit — socket — reddit-post