Back to skill

Security audit

subreddit-finder-pro

Security checks across malware telemetry and agentic risk

Overview

This skill is a Reddit marketing advisor, but it includes concrete tactics for avoiding moderation and disguising promotion.

Review carefully before installing. The subreddit discovery portions are useful, but the launch-playbook sections should be changed to require transparent affiliation disclosure, subreddit-rule compliance, and no moderation-evasion or hidden promotional funneling. Do not provide Reddit OAuth tokens unless the publisher documents least-privilege scopes and secure handling.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill asks users to provide a product URL and optionally a Reddit OAuth token, but does not present a clear, upfront warning about what data will be accessed, how tokens will be handled, or what privacy/security risks follow from sharing credentials. This creates a real risk of oversharing sensitive business information or granting unnecessary account access without informed consent.

Ssd 4

High
Confidence
98% confidence
Finding
The launch plan explicitly coaches users through a staged trust-building process designed to evade Reddit moderation heuristics and then promote a product with reduced detection risk. Instructions such as warming up an account, delaying promotion until karma is built, and using indirect posting patterns materially facilitate deceptive spam and platform-abuse behavior.

Ssd 2

High
Confidence
99% confidence
Finding
The skill advises users to avoid links in the main post and instead direct readers to discover the product via profile bio or comment history, framed as a way to avoid autobans while still driving traffic. That is a clear moderation-evasion tactic that disguises commercial promotion to bypass subreddit anti-spam controls.

Ssd 2

Medium
Confidence
95% confidence
Finding
The competitor-response guidance encourages users to insert promotional replies into complaint threads as a workaround for direct-link restrictions, using conversational placement to mask advertising intent. This increases the likelihood of deceptive astroturfing, spam complaints, and abuse of community discussions for covert lead capture.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.