reddit-research
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted content from Reddit discussions, which could potentially contain malicious instructions aimed at manipulating the agent's behavior. * Ingestion points: Data is retrieved from external Reddit threads, comments, and search results via tools such as reddit_app_post_details and reddit_app_post_comments (identified in SKILL.md and references/sandbase-api-map.md). * Boundary markers: The skill does not provide specific instructions or delimiters to the agent for isolating or treating retrieved content as untrusted data. * Capability inventory: The skill utilizes the sandbase_call_tool to interact with external APIs for data retrieval purposes. * Sanitization: There are no instructions for sanitizing or validating content fetched from external sources before it is processed by the agent.
Audit Metadata