devvit-skill-setup

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [Prompt Injection] (LOW): The skill modifies persistent instruction files (such as AGENTS.md and CLAUDE.md) to insert a directive: 'Always use the devvit-docs skill... without me having to explicitly ask.' This establishes a persistent behavioral override that mandates the use of a specific tool regardless of future user intent.- [External Downloads] (LOW): The troubleshooting section encourages users to execute 'npx add-skill reddit/devvit-skills'. The 'reddit' organization is not listed as a Trusted External Source, and npx involves fetching and executing code from a remote registry.- [Data Exposure] (SAFE): The skill accesses local configuration files within the workspace root but does not demonstrate patterns for credential exfiltration or unauthorized network communication.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 06:02 PM