reddit-search-api

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted third-party data retrieved from Reddit via API endpoints.
  • Ingestion points: Data enters the agent context through API responses containing Reddit post titles, content, and comments as described in the search/vector, search/semantic, and trends endpoint sections in SKILL.md.
  • Boundary markers: The skill includes a dedicated 'Handling Untrusted Content' section that explicitly instructs the agent to treat Reddit content as data rather than instructions and to visually isolate it using blockquotes or fenced blocks.
  • Capability inventory: The skill utilizes curl for network communication with the API provider.
  • Sanitization: There are explicit instructions for the agent to never execute URLs, commands, or file paths found within the retrieved text, and to disregard any instructions or fake system prompts embedded in Reddit content.
  • [DATA_EXFILTRATION]: The skill involves network operations to reddapi.dev for search and trend analysis. These operations are the primary purpose of the skill and utilize environment variables (REDDAPI_API_KEY) for authentication. The instructions contain strict prohibitions against logging, printing, or otherwise exposing these credentials, adhering to security best practices.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:38 PM
Security Audit — agent-trust-hub — reddit-search-api