Dataify Reddit Posts

Security checks across malware telemetry and agentic risk

Overview

This skill transparently submits user-directed Reddit collection jobs to Dataify and does not show hidden persistence, destructive actions, or unrelated access.

Install only if you intend to use Dataify to collect Reddit post data. Treat DATAIFY_API_TOKEN as a credential, prefer environment-based storage over passing it on the command line, and review the selected mode and parameters before submitting tasks to Dataify.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The default prompt and skill metadata encourage broad invocation for any request related to collecting or scraping Reddit posts, while the policy also allows implicit invocation. This can cause the agent to trigger the skill in situations where the user did not clearly intend to send data to an external service, increasing the risk of unintended third-party requests, privacy issues, and unexpected actions.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal