Back to skill

Security audit

Reddit

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it says for Reddit, but it gives an agent live posting and moderation power with weak guardrails and risky credential handling.

Review before installing. Use a dedicated Reddit app/account where possible, do not set REDDIT_USERNAME or REDDIT_PASSWORD for this skill, protect or delete ~/.reddit-token.json when not needed, and avoid letting an agent run posting or moderation commands without explicit human confirmation.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/reddit.mjs:175
Finding

Shell Command Injection During OAuth Browser Launch

Content
View full analysis
{ // Try to open browser automatically const cmd = process.platform === 'darwin' ? 'open' : process.platform === 'win32' ? 'start' : 'xdg-open'; exec(`${cmd} "${authUrl}"`); }); ``` ### Technical Analysis The OAuth URL incorporates `clientId`, obtained from the `REDDIT_CLIENT_ID` environment variable, without URL encoding. The resulting URL is then interpolated into a command string passed to Node.js `exec`, which invokes a system shell. Double quotes do not prevent all shell evaluation. On Unix-like systems, constructs such as command substitution using `$()` remain active inside double-quoted strings. Consequently, a malicious environment or configuration value can alter the command interpreted by the shell when the user runs the `login` command. The browser launch is legitimate functionality, but using a shell is unnecessary and exceeds the privilege needed merely to open a URL. ### Attack Path 1. An attacker gains the ability to influence the Skill's environment or configuration, including `REDDIT_CLIENT_ID`. 2. The attacker supplies a value containing shell syntax, such as a command-substitution expression. 3. The user or Agent invokes: ```bash node scripts/reddit.mjs login ``` 4. The malicious value is embedded in `authUrl`. 5. `exec` passes the constructed string to the operating-system shell. 6. The shell evaluates the injected syntax and executes the attacker's command with the privileges of the user running the Skill. This path req ...[truncated 624 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/reddit.mjs:37
Finding

OAuth Tokens Stored Without Explicitly Restrictive File Permissions

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/reddit.mjs:17
Finding

OAuth Flow Requests Permissions Beyond Implemented Functionality

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:17
Finding

Setup Documentation Unnecessarily Requests Reddit Account Passwords

Content
View full analysis
Remediation
View remediation
This Skill uses Reddit's interactive OAuth flow. Do not provide or store your Reddit username or password in environment variables. Users who previously followed the documentation should be advised to: 1. Remove the variables from shell profiles, Agent configuration, deployment manifests, and secret stores. 2. Restart affected processes so the credentials are no longer present in their environments. 3. Review version-control history and logs for accidental disclosure. 4. Rotate the Reddit password if it may have been exposed. 5. Prefer a dedicated application credential and narrowly scoped OAuth authorization. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation presents conflicting authentication guidance: setup instructs users to configure a Reddit 'script' app with username/password environment variables, while the notes say to run a login command once to authorize and mention a stored OAuth token. This mismatch can lead users to use an insecure or incorrect auth flow, mishandle credentials, or leave long-lived secrets on disk without understanding how authentication actually works.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The README encourages posting and moderation capabilities but does not clearly warn that these commands can create public content or perform destructive moderator actions such as removing or stickying posts. In an agent-skill context, lack of explicit safety framing increases the chance of unintended real-world actions by users or higher-level agents that treat the skill as routine automation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README instructs users to place Reddit username and password into environment variables without any guidance on secret handling, shell history exposure, process inspection risks, or using safer secret stores. In an agent environment, these credentials may be inherited broadly by subprocesses, logged, or exposed to unrelated tools, creating a substantial account-compromise risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README states that a token is saved to ~/.reddit-token.json but does not warn that this file contains reusable OAuth credentials that may grant ongoing posting or moderation access. Users may leave the file with weak permissions, sync it to cloud storage, or expose it through backups, making token theft more likely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill documents live posting and moderation commands, including destructive actions such as remove, lock, sticky, and approve, without any warning that they affect real Reddit content or recommending confirmation before execution. In an agent setting, this increases the chance of accidental harmful actions against production communities, especially if the agent is given broad instructions or misinterprets user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The setup instructions tell users to export Reddit client credentials, username, and password, but do not warn about the sensitivity of these secrets or the risks of shell history, process environment leakage, and local token storage. This can lead to credential exposure and account compromise if the environment or home directory is accessible to other users, logs, or tools.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script persists OAuth access and refresh tokens to ~/.reddit-token.json without setting restrictive file permissions or warning the user that long-lived credentials are being stored locally. On multi-user systems or in environments with weak home-directory protections, another local process or user could recover the refresh token and gain ongoing Reddit account access, including posting and moderation capabilities.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The CLI performs state-changing actions such as submit, reply, remove, approve, sticky, lock, and unlock immediately once invoked, with no confirmation prompt, dry-run mode, or explicit warning. In an agent or automation context, malformed arguments, prompt-influenced commands, or operator mistakes could cause unintended public posts or irreversible moderation actions on behalf of the authenticated user.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access, suspicious.exposed_secret_literal (+1 more)

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/reddit.mjs:252

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/reddit.mjs:26

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/reddit.mjs:30

Sensitive-looking file read is paired with a network send.

Warn
Code
suspicious.potential_exfiltration
Location
scripts/reddit.mjs:37