Back to skill

Security audit

reddit-lead-inbox

Security checks across malware telemetry and agentic risk

Overview

The skill is a coherent Reddit lead-generation assistant, but it includes under-disclosed persuasion guidance that pushes users toward private tracked DMs and disguising AI-written outreach as human-written.

Review this carefully before installing. Use it only for transparent, policy-compliant Reddit engagement, avoid fabricated personalization or intentional AI-disguise tactics, and confirm any Reddit or Stripe credentials are truly read-only and revocable.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Ssd 4

Medium
Confidence
91% confidence
Finding
This workflow explicitly coaches users to build trust in public and then shift targets into private DMs carrying tracked links, which normalizes evasive outreach and reduces transparency for recipients and moderators. In context, the skill is designed for lead generation at scale, so this pattern can facilitate deceptive spam tactics, user manipulation, and platform-policy evasion even if it stops short of full automation.

Ssd 4

High
Confidence
99% confidence
Finding
The skill tells users to add a personal memory and intentional typos/contractions so AI-generated outreach appears human-authored, which is a direct instruction to disguise automated persuasion as authentic personal speech. In a marketing/outreach skill, this materially increases deception risk, undermines informed consent, and can enable large-scale spam or impersonation-style social engineering.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.