reddit-search

Pass

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to use the postplus CLI utility suite for its primary operations. This includes postplus research collect for data gathering, postplus doctor for environment diagnostics, and postplus research schema for parameter discovery. These commands represent controlled execution of vendor-owned tools.
  • [PROMPT_INJECTION]: The skill defines a workflow for ingesting external content (Reddit post titles and body snippets) into the agent's context, which constitutes an indirect prompt injection surface.
  • Ingestion points: External data is ingested from Reddit via the postplus research collect command into result.json.
  • Boundary markers: While the skill provides clear instructions for data normalization and deduplication, it lacks explicit prompt delimiters or specific instructions for the agent to disregard instructions potentially embedded within the fetched Reddit snippets.
  • Capability inventory: The skill's primary capability is shell command execution via the postplus CLI toolset.
  • Sanitization: The instructions do not specify any sanitization, filtering, or escaping logic for the content of the snippet field retrieved from the external source.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 18, 2026, 02:21 AM
Security Audit — agent-trust-hub — reddit-search