Back to skill

Security audit

Reddit

Security checks for vulnerabilities and agentic risk

Overview

This Reddit skill is a disclosed connector wrapper that can read, post, edit, and delete Reddit content with confirmation gates for state-changing actions.

Install only if you intend to let agents use your connected Reddit account through OOMOL. Review proposed payloads before approving posts, edits, comments, or deletions, and be aware that first-time setup may require installing and signing into the oo CLI.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger language is excessively broad, directing use of this skill for 'ANY Reddit request' and 'Whenever a task involves Reddit.' In an agentic system, this can cause the skill to be invoked for loosely related or ambiguous tasks, increasing the chance of unnecessary connector access, unintended data exposure, or accidental execution of state-changing Reddit actions in the wrong context.

Static analysis

No suspicious patterns detected.