Back to skill

Security audit

Reddit Lead Prospecting

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Reddit lead-prospecting helper using Brave Search, with limited documentation and terminal-output hygiene issues but no evidence of credential theft, automatic posting, persistence, or destructive behavior.

Install only if you are comfortable providing a Brave Search API key and sending your search queries to Brave. Treat displayed search results as untrusted terminal output, and prefer a version that sanitizes terminal control characters. Also note that the code contains local post-template and metrics helpers beyond the three commands described in SKILL.md.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
reddit-prospecting.js:473
Finding

Unsanitized Remote Search Results Allow Terminal Escape-Sequence Injection

Content
View full analysis

Vulnerability Details

File Location: reddit-prospecting.js, lines 473-475
Vulnerability Type: Terminal escape-sequence injection through unsanitized remote content
Risk Level: Medium

Vulnerable Code

js
console.log(`   ${r.title}`);
console.log(`   ${r.snippet?.slice(0, 120) || ''}`);
console.log(`   ${r.url}\n`);

The values r.title, r.snippet, and r.url originate from the Brave Search API response. They are derived from externally indexed web content and are printed directly to the user's terminal without filtering terminal control characters.

Technical Analysis

Search-result titles, descriptions, and URLs are attacker-influenceable data. JSON parsing does not neutralize control characters represented through JSON escapes; once parsed, those characters can become active terminal input.

The 120-character truncation applied to the snippet limits its length but does not sanitize it. Depending on terminal capabilities and configuration, crafted ANSI or OSC escape sequences may alter displayed output, erase or rewrite text, create deceptive hyperlinks, change terminal state, or invoke terminal-supported features such as clipboard operations.

This is an output-sanitization flaw rather than shell command injection. The code does not pass the values to a shell, and no direct arbitrary-code-execution path was identified.

Attack Path

  1. An attacker publishes Reddit or other indexable content with crafted terminal escape sequences in a title, description, or URL.
  2. Brave Search indexes the attacker-controlled content.
  3. A user runs the skill's search command with a query that returns the crafted result.
  4. The Brave API supplies the malicious field in its JSON response.
  5. The skill maps the response into r.title, r.snippet, or r.url.
  6. Lines 473-475 print that value without control-character sanitization.
  7. A compatible terminal interprets the embedded sequence inste ...[truncated 606 chars]
Remediation
View remediation

Remediation Suggestions

  1. Treat all Brave Search response fields as untrusted input.
  2. Before terminal output, remove ANSI CSI sequences, OSC sequences, C1 controls, and unsafe C0 control characters. Preserve only explicitly required formatting characters, such as newline or tab.
  3. Apply sanitization to every remote field, including titles, descriptions, URLs, subreddit names, error messages derived from remote responses, and future API fields.
  4. Prefer a reputable, maintained ANSI-stripping library if dependencies are acceptable. Otherwise, implement and test a centralized terminal-safe formatting function rather than scattered regular expressions.
  5. Consider exposing a structured JSON output mode for automation so downstream consumers do not need to parse terminal-formatted text.
  6. Add regression tests containing CSI, OSC hyperlink, OSC clipboard, carriage-return, backspace, and other control-character payloads.
  7. Continue to avoid passing remote values to shells or command-execution APIs.

Example defensive structure:

js
function terminalSafe(value) {
  return String(value ?? '')
    // Strip OSC sequences.
    .replace(/\x1B\][^\x07]*(?:\x07|\x1B\\)/g, '')
    // Strip CSI and related ANSI sequences.
    .replace(/\x1B(?:[@-_]|\[[0-?]*[ -/]*[@-~])/g, '')
    // Strip remaining controls except tab and newline.
    .replace(/[\x00-\x08\x0B-\x1F\x7F-\x9F]/g, '');
}

console.log(`   ${terminalSafe(r.title)}`);
console.log(`   ${terminalSafe(r.snippet).slice(0, 120)}`);
console.log(`   ${terminalSafe(r.url)}\n`);

A maintained sanitizer is preferable because terminal escape syntax has edge cases that ad hoc filtering may miss.

Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The documented purpose understates the broader behavior detected in code, including scoring users/prospects, generating outbound Reddit content beyond comments, tracking engagement/attribution metrics, and using external API credentials despite empty declared permissions. This mismatch is dangerous because reviewers and users rely on metadata to assess risk; incomplete disclosure can hide data handling, automation, and external communication capabilities that materially change the security and compliance posture.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill declares no explicit tool scope or permissions even though it requires environment access to a Brave API key and, by implication, network access to an external service. This creates an authorization and transparency gap: operators may approve the skill believing it has no external capabilities, while it can still consume secrets and make outbound requests.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest says the skill is for finding buying-intent leads on Reddit via Brave Search, scoring posts, and generating value-first comments. This file goes beyond that scope by adding content-post generation and KPI tracking for karma, DMs, inquiries, and sign-ups, which are broader Reddit growth/marketing operations rather than lead discovery/comment drafting.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest emphasizes Brave-based Reddit prospecting without Reddit OAuth, plus post scoring and comment generation. The metrics tracker adds DM counts, DM replies, inbound inquiries, and sign-up attribution, which materially expands the described behavior into outbound/inbound funnel management.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill returns recommended posting times specifically in EST for all users, which is a natural-language locale policy constraint embedded in the output. Because it does not offer a user locale option or explain that the guidance is U.S.-specific, it may improperly force a specific locale assumption.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.