Back to skill

Security audit

Reddit Researcher

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Reddit research helper that searches public Reddit-related sources and writes local summaries, with no evidence of deception, privilege escalation, or destructive behavior.

Use this only for topics you are comfortable sending to search engines and Reddit. Review or clean the local cache and exports if the research topic, URLs, or summaries are sensitive in a shared workspace.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill claims keyword-based Reddit scanning via Bing/Reddit fallback, but the findings indicate it instead depends on a local input file of Reddit URLs and local caching not reflected in the description. This mismatch can cause users to unknowingly provide or process local files and create stored artifacts, expanding the attack surface beyond simple web research. In agent workflows, hidden file dependencies and storage behavior are security-relevant.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill claims keyword-based Reddit scanning via Bing/Reddit fallback, but the findings indicate it instead depends on a local input file of Reddit URLs and local caching not reflected in the description. This mismatch can cause users to unknowingly provide or process local files and create stored artifacts, expanding the attack surface beyond simple web research. In agent workflows, hidden file dependencies and storage behavior are security-relevant.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill claims keyword-based Reddit scanning via Bing/Reddit fallback, but the findings indicate it instead depends on a local input file of Reddit URLs and local caching not reflected in the description. This mismatch can cause users to unknowingly provide or process local files and create stored artifacts, expanding the attack surface beyond simple web research. In agent workflows, hidden file dependencies and storage behavior are security-relevant.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/scan.sh (reported line 62)May include surrounding context.

sh
# Direct Reddit search via their JSON API
      local encoded_query=$(echo "$query" | sed 's/ /%20/g')
      url="https://www.reddit.com/search.json?q=${encoded_query}&sort=relevance&t=month&limit=20"
      response=$(curl --silent --max-time 15 -L \
        -H "User-Agent: Mozilla/5.0 (compatible; research bot 1.0)" \
        "$url" 2>&1)
      echo "$response" | python3 -c "

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill advertises shell-based scripts but does not declare an explicit tool scope such as permissions or allowed-tools. That increases the chance an agent executes shell commands with broader capabilities than the user expects, reducing containment and auditability. In this context, the skill is network- and file-oriented, so missing scope is more dangerous than in a purely descriptive skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The description omits that user research queries and fetched Reddit URLs/content may be transmitted to third-party services such as search engines or Reddit. This is dangerous because user prompts, topics, and harvested content may contain sensitive business or personal information, and users are not adequately warned before exfiltration occurs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This shell script performs HTTP requests to Reddit and then writes the returned content into a local cache file. While there is a stderr progress message for processing URLs, there is no explicit user disclosure that remote content will be stored on disk under a cache directory, which matters because fetched post bodies and comments may contain sensitive or unexpected data.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script section for scan.sh states 'Searches Reddit for posts matching keywords using DuckDuckGo.' This directly conflicts with the manifest description and later notes, which describe Bing as primary and Reddit JSON API/Google as fallbacks specifically because DuckDuckGo may block automated queries.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The export feature creates a timestamped markdown file containing collected findings, but the description does not clearly warn that research outputs are persisted on disk. This can leak sensitive topics, URLs, or summaries to shared workspaces, backups, or later users of the same environment. The risk is lower than remote exfiltration but still material for agent workspaces.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The header comments describe a search order of Bing, then Google, then Reddit JSON API, but the only non-Bing web-search fallback implemented in the 'google' branch requests https://html.duckduckgo.com/html/. This is an intent/documentation mismatch rather than a mere omission because the comments explicitly name a different service than the code uses.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The comment at L051 says 'Google search via html.duckduckgo lite', which is internally contradictory to the engine name and the broader script comments that describe fallback to Google. The implementation at L052 clearly sends the request to html.duckduckgo.com, so the documentation does not match the actual behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.