reddit-community-research
Pass
Audited by Gen Agent Trust Hub on Jul 2, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted content from public Reddit posts and comments, which constitutes a potential surface for indirect prompt injection. However, this is assessed as safe due to the skill's restricted 'eyes, not hands' operational scope, which prevents any account interaction or data exfiltration. * Ingestion points: Reddit titles and upvoted comments via 'reddit/posts' and 'reddit/comments' endpoints. * Boundary markers: Not explicitly defined to isolate external data. * Capability inventory: Reading local marketing context files and producing research summaries. * Sanitization: None present.
- [EXTERNAL_DOWNLOADS]: The skill connects to the UnifAPI MCP server (mcp.unifapi.com) to access live Reddit data, which is its primary purpose and originates from the tool's own vendor.
Audit Metadata