Back to skill

Security audit

Reddapi

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only skill for using a third-party Reddit research API, with expected external API use and no hidden local execution.

Install only if you are comfortable sending search terms and research topics to reddapi.dev. Avoid secrets, customer lists, unreleased plans, personal data, or sensitive profiling queries, and review applicable privacy, outreach, and platform-policy obligations before using lead-generation outputs.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill prominently advertises a third-party Reddit data service but does not clearly warn users that their search terms, research topics, and potentially sensitive business queries will be transmitted to reddapi.dev. In a research and market-intelligence context, queries may contain confidential product plans, competitor names, customer pain points, or internal strategy, so lack of disclosure creates a real data-sharing and privacy risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The lead-generation feature encourages profiling and scoring people based on Reddit discussions without warning about privacy, ethical, or compliance implications. This is risky because users may use the tool to infer intent, categorize individuals or companies, and build outreach lists without understanding the downstream privacy or regulatory consequences.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

This example shows direct transmission of user-supplied query content to an external third-party API endpoint. In this skill's context, lead queries are especially sensitive because they can reveal business strategy, target customers, competitor monitoring plans, or profiling activity, and the documentation does not pair the transmission with a clear caution about sharing sensitive data.

Content

Scanner excerpt · SKILL.md (reported line 105)May include surrounding context.

POST /api/v1/leads (NEW!)

bash
curl -X POST "https://reddapi.dev/api/v1/leads" \
  -H "Authorization: Bearer ***" \
  -H "Content-Type: application/json" \
  -d '{"query": "people frustrated with CRM software", "limit": 20, "min_score": 70}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This semantic search example sends arbitrary natural-language queries to reddapi.dev, which is an external processor. Because the skill is intended for competitive analysis, niche discovery, and research, users may unknowingly disclose sensitive internal interests or proprietary investigation topics if the skill does not clearly communicate that these prompts leave the local environment.

Content

Scanner excerpt · SKILL.md (reported line 127)May include surrounding context.

POST /api/v1/search/semantic

bash
curl -X POST "https://reddapi.dev/api/v1/search/semantic" \
  -H "Authorization: Bearer ***" \
  -H "Content-Type: application/json" \
  -d '{"query": "best productivity tools for remote teams", "limit": 100}'

Static analysis

No suspicious patterns detected.