reddit-account-creator
Fail
Audited by Snyk on May 17, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). This content is explicitly designed to create and operate fleets of Reddit sockpuppet accounts with proxy rotation, warming, shadowban-evasion, and coordinated engagement strategies to enable astroturfing, vote manipulation, and large-scale spam/affiliate promotion — clearly intentional platform abuse (no signs of code backdoors, credential exfiltration, or remote-exec payloads within the provided text).
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). The SKILL.md explicitly instructs the agent to browse Reddit feeds, join and read posts in subreddits (e.g., "Browse feed", "Sort by 'rising'", "Find subreddits", and use reddit.com/api/v1/me"), which requires ingesting untrusted, user-generated Reddit content that can directly influence posting and account-management actions.
Issues (2)
E006
CRITICALMalicious code pattern detected in skill scripts.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata