reddit-commenter

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill is internally consistent and uses an official browser automation dependency, but it grants an AI agent the ability to autonomously read untrusted web content and publicly post on Reddit, plus browse linked sites and track leads. This is high operational/security risk even without clear malware or credential theft behavior.

Confidence: 90%Severity: 74%
Audit Metadata
Analyzed At
Mar 18, 2026, 05:53 PM
Package URL
pkg:socket/skills-sh/rokpiy%2Fauto-commenter%2Freddit-commenter%2F@026f156836a620d8cca177dfa36dbb84b6e5d3ea