Back to skill

Security audit

Reddit Marketing and GEO Skill

Security checks for vulnerabilities and agentic risk

Overview

This Reddit marketing skill is mostly transparent about its purpose, but it automatically creates a recurring background agent with broad web and browser access, so users should review it before installing.

Install only if you want a persistent Reddit-monitoring agent running on a schedule. Before enabling it, confirm the exact cron schedule and timezone, restrict browser or posting tools if possible, require explicit approval for every post and schedule change, and make sure you know how to pause or delete the background job.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T06 · System Persistence

Error
Location
SKILL.md:12
Finding

Recurring Background Sub-Agent Creates Cross-Session Persistence

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 12–24
Vulnerability Type: Scheduled cross-session background execution
Risk Level: High

Complete Code Snippet:

markdown
## Initialization
Upon first run, the primary agent must **spawn a specialized sub-agent** named `reddit-geo-marketing-agent`. This sub-agent inherits the tools and configuration below to operate independently of the main conversation thread.

## Configuration
- **Brand Name**: [Your Brand Name]
- **Website**: [Your URL]
- **Keywords**: [keyword1, keyword2, "best alternative to X"]
- **Default Schedule**: `0 9,18 * * *` (9:00 AM and 6:00 PM Daily)
- **User Modification**: Users can update the schedule by saying "Change my Reddit report time to [Time/Cron]."

## Workflow & Sub-Agent Instructions

### 1. The Cron Routine (Scheduled Execution)
- **Background Run**: The `reddit-geo-marketing-agent` is initialized via `sessions_spawn` to run in the background.
- **Pre-Trigger Action**: The sub-agent must begin its search/drafting process **30 minutes prior** to the scheduled reporting time to ensure the digest is ready.
- **Reporting**: At 9:00 AM and 6:00 PM, the sub-agent will deliver a summary of findings to the primary chat session using the `announce` delivery mode.

Technical Analysis

The skill mandates spawning an independently operating sub-agent on first run and assigns it a recurring cron schedule. This creates an execution mechanism that survives the initiating interaction and activates twice daily without requiring a fresh invocation.

The persistent agent inherits tools including web search, web fetching, browser access, and sub-agent spawning. Its documented workflow can therefore repeatedly access external content and prepare browser-based posting activity. The requirement for a separate approval before posting reduces the likelihood of unauthorized publication, but it does not eliminate the scheduled persi ...[truncated 1348 chars]

Remediation
View remediation

Remediation Suggestions

  • Do not spawn a background agent or create a recurring schedule automatically on first run.
  • Default to a one-shot workflow that executes only in direct response to a user request.
  • Before creating a scheduled task, obtain explicit and informed confirmation that displays:
    • The exact cron expression and effective time zone.
    • The sub-agent identity and execution frequency.
    • Every tool and external service available to the job.
    • The data sent to external websites.
    • Instructions for inspecting, pausing, and permanently deleting the job.
  • Use a separate, least-privileged tool profile for scheduled runs. Exclude browser posting and sub-agent spawning unless they are essential.
  • Keep browser submission disabled during background runs and require per-action user authorization immediately before every post.
  • Add expiration and execution-count limits so schedules do not remain active indefinitely.
  • Record auditable creation, execution, configuration-change, and deletion events for the scheduled job.
  • Require confirmation before schedule changes and validate cron input against safe frequency limits.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README explicitly advertises a background sub-agent, scheduled execution, web searches, and browser-based analysis, but it does not clearly disclose the extent of persistent automated network activity, what data may be collected, where it is sent, or how user-provided brand/keyword data is handled. For a skill that runs unattended and uses browsing capabilities, this lack of transparency increases the risk of unexpected data exposure, privacy issues, and user consent failures.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill allows schedule changes through a broad natural-language trigger ("Change my Reddit report time to [Time/Cron]") without defining a strict confirmation or parsing boundary. In a conversational agent that also spawns background jobs, ordinary dialogue, quoted text, or prompt-injected content could be misinterpreted as a scheduling command, causing unauthorized or unintended cron changes.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.