Atlas / MCP servers / arindam200 / Reddit

RedditSAFE

mcp/arindam200/reddit-3

Model Context Protocol server implementation for Reddit

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
10 10r · 0w · 0d
Transport
—
License
MIT
Stars
301
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

This repository contains a Model Context Protocol server implementation for Reddit that allows AI assistants to access and interact with Reddit content through PRAW (Python Reddit API Wrapper).

What is MCP?

The Model Context Protocol (MCP) is a standard for enabling AI assistants to interface with external services, tools, and data sources. This server implements the MCP specification to provide access to Reddit content.

To know more about MCP, Check this video

Features

  • Get detailed user information with engagement analysis
  • Retrieve user comment and post history with flexible filtering
  • Fetch and analyze top posts from any subreddit
  • Search for posts across all of Reddit or within specific subreddits using search terms
  • Get comprehensive subreddit statistics and health metrics
  • View trending subreddits with growth patterns
  • Create strategic posts with timing recommendations
  • Reply to posts and comments with engagement optimization
  • AI-driven insights and recommendations
  • Smart response formatting with engagement metrics

Installation

  1. Clone this repository
git clone https://github.com/Arindam200/reddit-mcp.git
cd reddit-mcp
  1. Connect to the MCP server

Copy the below json with the appropriate {{PATH}} values:

{
"mcpServers": {
"reddit": {
"command": "{{PATH_TO_UV}}", // Run `which uv` and place the output here
"args": [
"--directory",
"{{PATH_TO_SRC}}", // cd into the repo, run `pwd` and enter the output here
"run",
"server.py"
],
"env": {
"REDDIT_CLIENT_ID": "your_client_id",
"REDDIT_CLIENT_SECRET": "you
Read from source at commit 015673f21fd2OBSERVED · 2026-10-05
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add reddit-mcp -- uvx reddit-mcp
claude-desktop
{
  "mcpServers": {
    "reddit-mcp": {
      "command": "uvx",
      "args": [
        "reddit-mcp"
      ]
    }
  }
}
03

Exposed tools (10)

10 read · 0 write · 0 destructive.

ToolRiskDescription
get_submission_by_idreadGet a Reddit submission by its ID.
get_submission_by_urlreadGet a Reddit submission by its URL.
get_subreddit_inforeadGet information about a subreddit.
get_subreddit_statsreadGet statistics and information about a subreddit.
get_top_postsreadGet top posts from a subreddit.
get_trending_subredditsreadGet currently trending subreddits.
get_user_commentsreadGet a user
get_user_inforeadGet information about a Reddit user.
get_user_postsreadGet a user
search_postsreadSearch for Reddit posts using a search query.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (3)

LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:89
#### Read-only Tools (require only client credentials):
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:170
- Requires: All read-only credentials PLUS `username` and `password`
Why it matters. asks the agent to read credentials
INFOInventory / provenance · inv.oversize · CWE-1104
Demo.png
Demo.png
Why it matters. 1018772 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-05 · audit v0.4.1 · source sha 015673f21fd2full audit observations/trust-audit/mcp-server/arindam200__reddit-3.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-05015673f21fd2SAFEB89first audit
06

Questions

What is the Reddit MCP server?

Model Context Protocol server implementation for Reddit

What tools does Reddit expose?

10 in total: 10 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Reddit safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Reddit need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (015673f21fd2), read on 2026-10-05. The repository is watched and re-audited when it changes.

Advertisement