reddit-insights
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill identifies the risk of processing untrusted third-party content from Reddit.
- It includes defensive instructions in
SKILL.mddirecting the agent to ignore any embedded commands within post data (e.g., 'ignore previous instructions' or shell commands). - It mandates the use of blockquotes to visually separate untrusted results from the agent's own reasoning.
- [CREDENTIALS_SAFE]: API keys are managed securely through environment variables.
- The helper script
scripts/reddapi.pyprevents credential leakage by stripping sensitive headers before logging errors and ensuring the key only travels in the HTTP Authorization header. SKILL.mdcontains clear developer guidelines prohibiting the echoing or hardcoding of the literal API key value.
Audit Metadata