Back to skill

Security audit

RedditAds Intelligence

Security checks across malware telemetry and agentic risk

Overview

The skill is a Reddit ads marketing-analysis prompt with disclosed data inputs and no executable install code or hidden automatic account actions.

Before installing, users should understand that the skill may require sharing aggregated Reddit Ads performance exports and competitor names, and they should verify any third-party data-source access, benchmark accuracy, language-tier limits, and legal or platform-policy assumptions for their own use case.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
87% confidence
Finding
The skill explicitly states 'English only' in the Starter tier, which can cause the agent to refuse or degrade service for users in other languages without the user's informed consent. In this context, the skill itself is largely bilingual and targeted at marketing intelligence, so silently enforcing a language restriction is a real quality and fairness issue rather than a direct security exploit, but it can still lead to exclusionary or misleading behavior.

VirusTotal

59/59 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.