social-reply-bot

Fail

Audited by Snyk on Aug 20, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.80). These URLs include a direct raw GitHub shell script (curl https://raw.githubusercontent.com/.../install.sh | bash) and repository clone endpoints from an individual/unknown GitHub account — executing remote .sh content or blindly cloning/running code from unvetted personal repos is a high-risk vector for malware.

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 0.90). The code implements deliberate, automated social-media outreach (karma warmup + targeted replies) that scrapes user posts and sends their content/URLs to third‑party LLMs for reply generation and lead extraction, and it automates account login/session persistence — behavior consistent with deceptive/astroturfing and user-data exfiltration to external services.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). The skill’s required runtime workflow reads outsider-authored free text from X/Twitter search results and tweet text via browse-controlled URLs (bot/x_bot.py → _search_posts opens https://x.com/search?q=… then extracts StaticText snippets for generate_reply/analyze_lead), and similarly from Reddit posts/comments via old.reddit.com browsing (bot/reddit_bot.py → _get_subreddit_posts/_navigate_and_get_content open https://old.reddit.com/... and scrape StaticText snippets for generate_reply/analyze_lead).

Issues (3)

E005
CRITICAL

Suspicious download URL detected in skill instructions.

E006
CRITICAL

Malicious code pattern detected in skill scripts.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 20, 2026, 02:28 PM
Issues
3
Security Audit — snyk — social-reply-bot