Back to skill

Security audit

reddit-mention-radar

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Reddit brand-monitoring and marketing-response skill, with no executable code, but users should apply its reputation and competitor-outreach guidance carefully.

Install only if you want Reddit-focused brand, competitor, and reputation monitoring. Review any generated replies yourself, disclose affiliations, follow Reddit and advertising rules, and avoid pressuring users to revise criticism or targeting competitor complaints in a misleading way.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger keywords are broad, generic marketing phrases such as 'reddit seo' and 'ai citations', which can cause the skill to activate for unrelated user requests. Over-broad routing is dangerous because it can silently steer users into this skill's persuasive monitoring/playbook even when they did not ask for competitor interception or reputation-response guidance.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The invocation guidance uses open-ended conditions like 'wants GEO check' and 'competitor intel' without clear limits on when the skill should not run. In context, this matters because the skill contains tactics for reputation shaping and competitor interception, so ambiguous activation increases the chance of unsolicited or context-inappropriate use.

Ssd 4

Medium
Confidence
85% confidence
Finding
This section operationalizes monitoring competitor complaints and timing outreach to insert the operator's product into vulnerable moments. That is dangerous because it turns the skill into a persuasion/manipulation workflow targeting distressed users, creating reputational, policy, and trust harms even if no technical system is compromised.

Ssd 4

Medium
Confidence
88% confidence
Finding
The skill prescribes a staged process to remediate publicly, move interaction into private channels, and then ask the critic to edit the original negative review. This is dangerous because it facilitates review manipulation and pressure on users to rewrite criticism, undermining authenticity and potentially violating platform or consumer-protection rules.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.