reddit-automation

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: the skill is broadly aligned with Reddit automation, and the Rube MCP endpoint appears to be an official same-org service, so this is not clearly malicious. However, it routes authenticated Reddit operations through an intermediary MCP service, understates setup/auth requirements, and grants the agent the ability to perform public posting and deletion actions based on untrusted external content, which makes the overall risk medium.

Confidence: 83%Severity: 61%
Audit Metadata
Analyzed At
Mar 18, 2026, 03:31 PM
Package URL
pkg:socket/skills-sh/davepoon%2Fbuildwithclaude%2Freddit-automation%2F@708401367fa727d4fc950570fe17828c8a4d832e