reddit-scraper
Pass
Audited by Gen Agent Trust Hub on May 17, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: A comprehensive review of the skill instructions and metadata reveals no malicious patterns or security risks. The skill is primarily focused on providing documentation for web scraping workflows.
- [NO_CODE]: The skill consists of a single markdown file containing instructions and configuration templates (JSON/Bash). It does not include any Python, Node.js, or shell scripts that would execute in the agent's environment.
- [PROMPT_INJECTION]: No attempts to override agent constraints, bypass safety filters, or extract system prompts were detected in the text or metadata.
- [PROMPT_INJECTION]: The skill identifies a surface for indirect prompt injection by instructing the agent to ingest external content from Reddit:
- Ingestion points: reddit.com JSON endpoints for posts, comments, search results, and user profiles.
- Boundary markers: None specified in the instructions for isolating scraped content.
- Capability inventory: None; the skill provides no tools or executable code, though the agent may use its own tools to process the data.
- Sanitization: No sanitization or filtering of scraped content is mentioned.
- [EXTERNAL_DOWNLOADS]: The skill references BirdProxies for residential proxy rotation. These references are consistent with the skill's stated purpose and do not involve the download of untrusted code or binaries.
Audit Metadata