social-reply-bot
Fail
Audited by Snyk on Aug 20, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 0.80). These URLs include a direct raw GitHub shell script (curl https://raw.githubusercontent.com/.../install.sh | bash) and repository clone endpoints from an individual/unknown GitHub account — executing remote .sh content or blindly cloning/running code from unvetted personal repos is a high-risk vector for malware.
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 0.90). The code implements deliberate, automated social-media outreach (karma warmup + targeted replies) that scrapes user posts and sends their content/URLs to third‑party LLMs for reply generation and lead extraction, and it automates account login/session persistence — behavior consistent with deceptive/astroturfing and user-data exfiltration to external services.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The skill’s required runtime workflow reads outsider-authored free text from X/Twitter search results and tweet text via browse-controlled URLs (bot/x_bot.py → _search_posts opens https://x.com/search?q=… then extracts StaticText snippets for generate_reply/analyze_lead), and similarly from Reddit posts/comments via old.reddit.com browsing (bot/reddit_bot.py → _get_subreddit_posts/_navigate_and_get_content open https://old.reddit.com/... and scrape StaticText snippets for generate_reply/analyze_lead).
Issues (3)
E005
CRITICALSuspicious download URL detected in skill instructions.
E006
CRITICALMalicious code pattern detected in skill scripts.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata