reddit

Fail

Audited by Socket on Mar 17, 2026

2 alerts found:

SecurityObfuscated File
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The stated purpose broadly matches Reddit monitoring and report generation, and no credential theft or proxy exfiltration is explicit. However, the skill's real operational core is an undocumented `reddit.sh` executable with unknown provenance, and the agent is instructed to run it repeatedly with network and file-write effects. That unverifiable CLI makes the skill high security risk despite limited evidence of confirmed malware.

Confidence: 84%Severity: 74%
Obfuscated FileHIGH
scripts/test/test_algo_scheduling.sh

The code fragment is a benign test harness for scheduling-related algorithms. It uses predefined JSON inputs, sources helper modules, and asserts on algorithm outputs. No malicious activity, data exfiltration, or credential handling is evident in this isolated fragment. Security risk is low within the tested scope, though broader project context should be reviewed to ensure downstream components remain safe.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 17, 2026, 05:55 AM
Package URL
pkg:socket/skills-sh/sky-flux%2Fskills%2Freddit%2F@b36fa42f6658219de1592088572eef51c914f18e