reddit-research

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted third-party content from Reddit (post titles, body text, and comments) via the reddapi.dev API. This constitutes a vulnerability surface where malicious instructions could be embedded in the retrieved data.
  • Ingestion points: External data enters the agent context through search results and trend data fetched from https://reddapi.dev (defined in SKILL.md).
  • Boundary markers: The skill explicitly instructs the agent to visually separate quoted results using blockquotes or fenced blocks to prevent them from being mistaken for system instructions.
  • Capability inventory: The agent uses curl for network operations and python3 for data processing (defined in SKILL.md).
  • Sanitization: The instructions include clear rules to ignore any commands or "ignore previous instructions" patterns found within the Reddit content and to avoid executing any URLs or shell commands found in user text.
  • [COMMAND_EXECUTION]: The skill provides research playbooks that involve executing shell commands (curl) and piping output to a Python one-liner (python3 -c) for data processing.
  • Evidence: SKILL.md includes a template for trend tracking that parses JSON using python3 -c. The Python script is a static, safe template for formatting growth rates and post counts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:36 PM
Security Audit — agent-trust-hub — reddit-research