reddit-research
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted third-party content from Reddit (post titles, body text, and comments) via the reddapi.dev API. This constitutes a vulnerability surface where malicious instructions could be embedded in the retrieved data.
- Ingestion points: External data enters the agent context through search results and trend data fetched from
https://reddapi.dev(defined inSKILL.md). - Boundary markers: The skill explicitly instructs the agent to visually separate quoted results using blockquotes or fenced blocks to prevent them from being mistaken for system instructions.
- Capability inventory: The agent uses
curlfor network operations andpython3for data processing (defined inSKILL.md). - Sanitization: The instructions include clear rules to ignore any commands or "ignore previous instructions" patterns found within the Reddit content and to avoid executing any URLs or shell commands found in user text.
- [COMMAND_EXECUTION]: The skill provides research playbooks that involve executing shell commands (
curl) and piping output to a Python one-liner (python3 -c) for data processing. - Evidence:
SKILL.mdincludes a template for trend tracking that parses JSON usingpython3 -c. The Python script is a static, safe template for formatting growth rates and post counts.
Audit Metadata