Phy Reddit Cultivate
Security checks across static analysis, malware telemetry, and agentic risk
Overview
The skill's instructions match its stated goal (automating a logged-in Chrome session to interact with Reddit), but they require high-privilege macOS automation (AppleEvents/System Events, clipboard and keyboard control) that can access session cookies and perform account actions — a disproportionate risk that should be reviewed before use.
This skill does exactly what it says: it automates your real, logged-in Chrome session on macOS to scan Reddit and post comments by running JavaScript in the page and using keyboard automation. Before installing or running it, consider: 1) macOS permissions: you'll need to allow AppleEvents and enable accessibility for automation — these permissions let scripts control your browser and keyboard and can be abused to exfiltrate session data. 2) Account risk: automated posting can violate Reddit's terms of service and lead to account suspension or bans. 3) Privilege risk: the scripts run with your browser's cookies and session; arbitrary JS execution could leak passwords, cookies, or other site data. 4) Trust: the skill is instruction-only with no source code repository or provenance; if you proceed, review every script/JS snippet manually, run it on a throwaway/test account or isolated macOS user, and do not grant system automation permissions unless you understand and accept the risks. If you cannot audit the JavaScript being executed in your browser, avoid using this skill.
Static analysis
No static analysis findings were reported for this release.
VirusTotal
No VirusTotal findings
Risk analysis
No visible risk-analysis findings were reported for this release.
