Back to skill

Security audit

Reddit API

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward guide for using a paid third-party Reddit data API, with its network and payment model disclosed.

Install only if you are comfortable sending Reddit search terms, usernames, subreddit names, post IDs, and any Bearer key to reddit.fetcher.sh. Avoid submitting secrets, confidential internal terms, or regulated personal data, and keep control over prepaid credits, x402 wallet signing, and MCP tools that can make paid calls.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
95% confidence
Finding
The skill instructs users to send arbitrary search keywords, usernames, subreddit names, and post IDs to an external service (`reddit.fetcher.sh`) but does not clearly warn that these user-provided values will be transmitted to a third party. This creates a privacy and data-handling risk, especially if users include sensitive investigation terms, internal project names, or personal identifiers in queries.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:42