reddit-pain-workflow

Security checks across malware telemetry and agentic risk

Overview

This skill openly describes a Reddit-to-GitHub reporting workflow, and the external collection and publishing behavior matches that purpose.

Before installing or running it, confirm which script or repository supplies reddit_pain_workflow.py, use a test or dedicated GitHub repository, and give any GitHub token only the minimum permissions needed to push the generated reports.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly describes scheduled Reddit scanning, report generation, and automatic pushes to GitHub, but the documentation does not clearly warn users that it performs unattended data collection and writes to an external repository. This can lead users to run automation without understanding outbound actions, token usage, repository modification risk, or compliance implications, making accidental data disclosure or unwanted publishing more likely.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal