devvit-skill-setup
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [Prompt Injection] (LOW): The skill modifies persistent instruction files (such as AGENTS.md and CLAUDE.md) to insert a directive: 'Always use the devvit-docs skill... without me having to explicitly ask.' This establishes a persistent behavioral override that mandates the use of a specific tool regardless of future user intent.- [External Downloads] (LOW): The troubleshooting section encourages users to execute 'npx add-skill reddit/devvit-skills'. The 'reddit' organization is not listed as a Trusted External Source, and npx involves fetching and executing code from a remote registry.- [Data Exposure] (SAFE): The skill accesses local configuration files within the workspace root but does not demonstrate patterns for credential exfiltration or unauthorized network communication.
Audit Metadata