thread-writer

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides a template for a curl command to post content to the Reddit API. This involves executing a shell command with user-controlled variables like {title} and {body}. If the agent interpolates these variables directly into the shell string without proper escaping or sanitization, it could lead to arbitrary command execution on the host system.
  • Evidence: SKILL.md contains a reference implementation: curl -s -X POST "https://oauth.reddit.com/api/submit" ... -d "sr={subreddit}&kind=self&title={title}&text={body}&api_type=json".
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process 'Source material' such as blog posts, research, or data from external sources. This creates an attack surface where malicious instructions embedded in the input material could attempt to influence the agent's behavior, particularly given its access to the Bash tool.
  • Ingestion points: The 'Source material' requirement in the 'Gathering Requirements' section.
  • Boundary markers: None specified in the prompt instructions to isolate external data.
  • Capability inventory: The skill has access to the Bash tool, which is used for network operations (Reddit API posting).
  • Sanitization: No specific sanitization or validation logic is defined for the external source material before it is processed or used in shell commands.
  • [DATA_EXFILTRATION]: The skill identifies and uses sensitive environment variables (REDDIT_ACCESS_TOKEN, REDDIT_CLIENT_ID, REDDIT_CLIENT_SECRET) to interact with external APIs. While this is standard for API integrations, it represents access to credentials that could be targeted by a successful prompt injection attack.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 12:48 PM