reddit-search-api
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted third-party data retrieved from Reddit via API endpoints.
- Ingestion points: Data enters the agent context through API responses containing Reddit post titles, content, and comments as described in the
search/vector,search/semantic, andtrendsendpoint sections inSKILL.md. - Boundary markers: The skill includes a dedicated 'Handling Untrusted Content' section that explicitly instructs the agent to treat Reddit content as data rather than instructions and to visually isolate it using blockquotes or fenced blocks.
- Capability inventory: The skill utilizes
curlfor network communication with the API provider. - Sanitization: There are explicit instructions for the agent to never execute URLs, commands, or file paths found within the retrieved text, and to disregard any instructions or fake system prompts embedded in Reddit content.
- [DATA_EXFILTRATION]: The skill involves network operations to
reddapi.devfor search and trend analysis. These operations are the primary purpose of the skill and utilize environment variables (REDDAPI_API_KEY) for authentication. The instructions contain strict prohibitions against logging, printing, or otherwise exposing these credentials, adhering to security best practices.
Audit Metadata