Skill flagged — suspicious patterns detected
ClawHub Security flagged this skill as suspicious. Review the scan results before using.
Reddit Engagement
v1.0.0Create and execute robust Reddit engagement workflows (create post, add comment, upvote) using browser accessibility-tree semantics instead of brittle DOM id...
⭐ 0· 252·1 current·1 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Suspicious
medium confidencePurpose & Capability
Functionality (compose posts/comments, upvote, analyze subreddits via accessibility snapshots) is coherent with the name/description. However the skill reads and appends to workspace files (PERSONA.md, references/sub-archives.md) and writes logs after posting, yet registry metadata declares no required config paths; that omission is inconsistent with the skill's runtime needs.
Instruction Scope
SKILL.md instructs the agent to navigate Reddit pages, snapshot accessibility trees, extract and analyze subreddit metadata, compose content using PERSONA.md, and append new profiles to references/sub-archives.md and usage logs to PERSONA.md. Those file reads/writes are outside what the registry metadata declared and are materially important to runtime. The instructions also include explicit anti-AI/evade-detection tactics (deliberately introduce linguistic errors, avoid 'polite assistant' phrasing) which increase misuse potential (astroturfing, deceptive campaigns).
Install Mechanism
No install spec and no code files — instruction-only skill. Low installation risk because it doesn't download or write new binaries.
Credentials
No environment variables or external credentials requested, which is proportionate. The skill assumes an authenticated browser session but does not declare or require any credential/config path for that. The lack of declared config paths is inconsistent with its explicit need to read/write workspace files (PERSONA.md, references/*).
Persistence & Privilege
always:false and normal autonomous invocation settings. The skill writes to workspace files (append new subreddit profiles and log used persona content) but does not request permanent platform-level privileges or modify other skills. The fact that it modifies workspace files should be disclosed in the registry metadata.
What to consider before installing
This skill appears to do what it says (automate Reddit actions using accessibility-tree semantics), but there are important concerns you should weigh before installing:
- The SKILL.md explicitly reads and appends to workspace files (PERSONA.md and references/sub-archives.md). The registry metadata lists no required config paths — confirm you are comfortable with the skill reading and modifying those files and back them up first.
- The guidance intentionally teaches ways to evade 'AI' signals and to emulate human posting patterns. That increases the risk of misuse (astroturfing, deception) and could violate Reddit's terms of service or get an account suspended. Decide whether you accept that risk.
- The skill assumes a browser is open and authenticated; it does not request a Reddit API key — it will rely on your active session. Ensure you trust the environment where the agent will run.
- If you plan to use real personal facts, review PERSONA.md to ensure it contains only information you want the agent to publish. The skill requires writing a usage log to PERSONA.md — consider the privacy implications.
Recommendations before enabling: review and approve the exact workspace files the skill will access/modify, back up PERSONA.md and references/*, and consider limiting the agent's ability to auto-publish (require manual confirmation for every post/comment). If you need stronger assurance, ask the author to update registry metadata to declare required config paths and to include an explicit consent step for file writes and publishing.Like a lobster shell, security has layers — review code before you run it.
latestvk974z7r1hwf763dxdv2js36qvn82fnv5
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
