reddit-insights

Pass

Audited by Gen Agent Trust Hub on Aug 8, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill includes explicit instructions for handling untrusted third-party data. It warns the agent to ignore commands (such as "ignore previous instructions") that might be present in Reddit post content, which mitigates indirect prompt injection risks.
  • [CREDENTIALS_UNSAFE]: Credential management follows industry best practices. The skill utilizes environment variables for the API key and establishes strict rules for the agent to avoid logging, echoing, or leaking the secret in error messages.
  • [EXTERNAL_DOWNLOADS]: The skill makes legitimate network requests to the dedicated API service at reddapi.dev. These requests are limited to the service's primary function and do not involve any unauthorized domains.
  • [NO_CODE]: The helper script is implemented using only the Python standard library. It does not require installing external packages or downloading remote scripts, which minimizes the supply chain attack surface.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 8, 2026, 07:55 AM
Security Audit — agent-trust-hub — reddit-insights