reddit-scraper

Pass

Audited by Gen Agent Trust Hub on May 17, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: A comprehensive review of the skill instructions and metadata reveals no malicious patterns or security risks. The skill is primarily focused on providing documentation for web scraping workflows.
  • [NO_CODE]: The skill consists of a single markdown file containing instructions and configuration templates (JSON/Bash). It does not include any Python, Node.js, or shell scripts that would execute in the agent's environment.
  • [PROMPT_INJECTION]: No attempts to override agent constraints, bypass safety filters, or extract system prompts were detected in the text or metadata.
  • [PROMPT_INJECTION]: The skill identifies a surface for indirect prompt injection by instructing the agent to ingest external content from Reddit:
  • Ingestion points: reddit.com JSON endpoints for posts, comments, search results, and user profiles.
  • Boundary markers: None specified in the instructions for isolating scraped content.
  • Capability inventory: None; the skill provides no tools or executable code, though the agent may use its own tools to process the data.
  • Sanitization: No sanitization or filtering of scraped content is mentioned.
  • [EXTERNAL_DOWNLOADS]: The skill references BirdProxies for residential proxy rotation. These references are consistent with the skill's stated purpose and do not involve the download of untrusted code or binaries.
Audit Metadata
Risk Level
SAFE
Analyzed
May 17, 2026, 04:09 PM
Security Audit — agent-trust-hub — reddit-scraper