Back to skill

Security audit

Reddit Researcher Agent

Security checks for vulnerabilities and agentic risk

Overview

This skill performs disclosed Reddit research tasks with expected network fetching and local report files, with only documentation and scoping quality issues.

Install only if you are comfortable with the skill making outbound requests to search engines and Reddit, and writing cached Reddit content plus markdown exports locally. Treat its summaries as simple extraction rather than deep analysis, and expect the search-engine documentation to be imprecise.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

There is a clear description-behavior mismatch. The declared purpose centers on collecting Reddit posts via Bing/Reddit APIs and summarizing research findings. The actual code chunk only formats and saves a preexisting summary file into a markdown export. While exporting could be a supporting part of a larger Reddit research workflow, this specific code does not implement the core declared functionality and instead performs a different, undeclared primary action: report export/file generation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The core purpose mostly aligns: the code searches for Reddit posts by keyword and uses Bing primarily with Reddit API fallback. However, the declared description claims it will 'summarize findings,' while the code only returns raw result links/titles and a rough count. Additionally, the description emphasizes Bing primary plus Reddit JSON API fallback due to DuckDuckGo blocking, but the implementation still includes a final fallback to html.duckduckgo.com despite describing DuckDuckGo blocking as a reason for replacement. These are material description-to-behavior mismatches, though there is no evidence of unrelated or harmful undeclared behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description emphasizes discovering Reddit posts by matching keywords via Bing with Reddit JSON fallback. The supplied code only summarizes already-identified Reddit URLs from a provided file. Its network behavior is limited to fetching each supplied Reddit URL as JSON, plus local caching. While summarization of Reddit content is consistent with part of the description, the primary discovery/search capability is missing, and the stated Bing-based search behavior is not present. That is a material description-to-behavior mismatch.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/scan.sh (reported line 62)May include surrounding context.

sh
# Direct Reddit search via their JSON API
      local encoded_query=$(echo "$query" | sed 's/ /%20/g')
      url="https://www.reddit.com/search.json?q=${encoded_query}&sort=relevance&t=month&limit=20"
      response=$(curl --silent --max-time 15 -L \
        -H "User-Agent: Mozilla/5.0 (compatible; research bot 1.0)" \
        "$url" 2>&1)
      echo "$response" | python3 -c "

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill declares shell-capable behavior via scripts and a curl dependency but does not define any explicit tool scope such as permissions or allowed-tools. This can lead to overbroad execution in agent environments, making it easier for the skill to invoke shell/network actions beyond what a reviewer or runtime policy expects.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description says to use the skill when 'researching Reddit communities, finding pain points, or gathering user feedback on a topic,' which is a broad natural-language trigger without clear scope limits or exclusion conditions. In a skill-selection context, this could overlap with many generic research requests and cause unintended invocation.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The instruction 'Search Reddit for posts and comments matching your keywords, extract insights and pain points' describes capability but does not define activation constraints or non-applicable cases. For markdown skill docs, the lack of explicit trigger scope or negative examples can make invocation criteria overly broad.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

Line L30 states that scan.sh searches Reddit posts using DuckDuckGo. However, the manifest description at L03 and the notes at L76 describe Bing as primary, with Reddit JSON API and Google as fallbacks, explicitly emphasizing operation when DuckDuckGo blocks automated queries. This is an active contradiction in the skill's own documentation about what the script does.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The comment says this branch is a 'Google search' fallback, yet the URL used is https://html.duckduckgo.com/html/, which is DuckDuckGo's HTML endpoint rather than Google. This is an active contradiction in the code documentation, not merely an omitted detail.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.