reddit-thread-analyzer

Pass

Audited by Gen Agent Trust Hub on Feb 16, 2026

Risk Level: LOWPROMPT_INJECTION
Full Analysis
  • [Indirect Prompt Injection] (LOW): The skill is designed to ingest and process untrusted external content from Reddit, which poses a risk of indirect prompt injection where malicious instructions embedded in comments could influence the agent. 1. Ingestion points: Reddit thread titles, bodies, and comments retrieved via the WebFetch tool as described in SKILL.md. 2. Boundary markers: Absent; there are no instructions to the agent to use delimiters or to disregard potential instructions found within the fetched data. 3. Capability inventory: Limited to data analysis, sentiment extraction, and markdown report generation; no file writing, arbitrary command execution, or network exfiltration capabilities are present in the provided instructions. 4. Sanitization: Absent; the instructions explicitly direct the agent to quote comments directly, which may include adversarial text.
Audit Metadata
Risk Level
LOW
Analyzed
Feb 16, 2026, 06:35 AM