reddit-commenter

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
BATCH.md

This document describes a batch-mode Reddit commenting automation workflow that orchestrates reading local tracking files, selecting subreddits by priority, composing comments using templates and personalization, posting to Reddit, and updating local leads/tracking. No executable code is provided, so there is no direct evidence of malware, obfuscation, or embedded backdoors in this artifact. However, the described automation poses moderate security and abuse risks (spam/astroturfing, potential for credential misuse depending on implementation). I recommend reviewing the actual implementation for credential handling, network endpoints, comment-generation logic (to detect templated/low-quality or invasive content), adaptive rate-limit/backoff behavior, and any hard-coded secrets before trusting or deploying the tool.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 15, 2026, 09:38 PM
Package URL
pkg:socket/skills-sh/rokpiy%2Fauto-commenter%2Freddit-commenter%2F@026f156836a620d8cca177dfa36dbb84b6e5d3ea