reddit-insights

Warn

Audited by Socket on Apr 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's purpose is coherent, and the requested API credential is proportionate for a Reddit search service, but the install path is not internally consistent with the vendor's current official documentation. The key risk is an unverified `npx`-installed MCP package that receives the API key. This looks more like install/provenance risk than confirmed malware, but it is too inconsistent to rate benign.

Confidence: 87%Severity: 78%
Audit Metadata
Analyzed At
Apr 4, 2026, 09:09 AM
Package URL
pkg:socket/skills-sh/sales-skills%2Fsales%2Freddit-insights%2F@4eff559011133c0b2f376f3d366297ede754998a