reddit-readonly
Warn
Audited by Snyk on Feb 15, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). The skill explicitly fetches and reads user-generated content from Reddit via public JSON endpoints (see SKILL.md: "Browse and search Reddit in read-only mode using public JSON endpoints" and commands like posts/search/comments/thread), so the agent will ingest untrusted third-party posts and comments that could contain malicious instructions.
Audit Metadata