Back to skill

Security audit

Reddit Researcher Agent

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward Reddit research helper, but its searches can send your keywords to external search providers and Reddit.

Install only if you are comfortable sending research terms, subreddit names, and Reddit URLs to external services such as Bing, DuckDuckGo, and Reddit. Avoid using confidential project names or sensitive topics, and review or clear the generated cache and export files after use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding
The skill declares a shell capability via required binaries (`curl`) but does not declare corresponding permissions, creating a transparency and policy-enforcement gap. This can lead to network-capable execution without explicit approval, which is risky because the skill is designed to fetch remote content and write cached/output files.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill documentation describes fetching Reddit content over the network and exporting results to disk without warning the user about outbound requests or file creation. In agent environments, undisclosed network access and writes can expose sensitive queries, create unexpected artifacts, or violate user expectations and operational policy.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal