reddit-account-creator

Fail

Audited by Snyk on May 17, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). This content is explicitly designed to create and operate fleets of Reddit sockpuppet accounts with proxy rotation, warming, shadowban-evasion, and coordinated engagement strategies to enable astroturfing, vote manipulation, and large-scale spam/affiliate promotion — clearly intentional platform abuse (no signs of code backdoors, credential exfiltration, or remote-exec payloads within the provided text).

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 1.00). The SKILL.md explicitly instructs the agent to browse Reddit feeds, join and read posts in subreddits (e.g., "Browse feed", "Sort by 'rising'", "Find subreddits", and use reddit.com/api/v1/me"), which requires ingesting untrusted, user-generated Reddit content that can directly influence posting and account-management actions.

Issues (2)

E006
CRITICAL

Malicious code pattern detected in skill scripts.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
CRITICAL
Analyzed
May 17, 2026, 04:09 PM
Issues
2
Security Audit — snyk — reddit-account-creator