reddit-insights

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies the risk of processing untrusted third-party content from Reddit.
  • It includes defensive instructions in SKILL.md directing the agent to ignore any embedded commands within post data (e.g., 'ignore previous instructions' or shell commands).
  • It mandates the use of blockquotes to visually separate untrusted results from the agent's own reasoning.
  • [CREDENTIALS_SAFE]: API keys are managed securely through environment variables.
  • The helper script scripts/reddapi.py prevents credential leakage by stripping sensitive headers before logging errors and ensuring the key only travels in the HTTP Authorization header.
  • SKILL.md contains clear developer guidelines prohibiting the echoing or hardcoding of the literal API key value.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 06:09 AM
Security Audit — agent-trust-hub — reddit-insights