RedditBLOCK
⚙️ A Model Context Protocol (MCP) that provides tools for fetching and creating Reddit content
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A Model Context Protocol (MCP) server for interacting with Reddit - fetch posts, comments, user info, and create content.
[](https://www.npmjs.com/package/reddit-mcp-server) [](https://www.npmjs.com/package/reddit-mcp-server) [](https://github.com/jordanburke/reddit-mcp-server/stargazers) [](https://opensource.org/licenses/MIT)
Features at a Glance
375fc8c78f5fOBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add reddit-mcp-server --env REDDIT_CLIENT_SECRET=${REDDIT_CLIENT_SECRET} --env REDDIT_PASSWORD=${REDDIT_PASSWORD} -- npx -y [email protected]Exposed tools (19)
13 read · 5 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
browse_subreddit | read | Browse a subreddit — or the authenticated home feed when no subreddit is given — by sort order: hot, new, top, rising, or controversial. Read-only; works without credentials via RSS fallback (titles and links only, no scores or comment counts). |
create_post | write | Create a new text or link post in a subreddit. Mutating and NOT idempotent — each call publishes a separate post. Requires REDDIT_USERNAME and REDDIT_PASSWORD; fails without them. Returns the new post |
edit_comment | write | Replace the text of one of your own comments. Mutating and idempotent (same text → same result); it overwrites the previous content. Requires REDDIT_USERNAME and REDDIT_PASSWORD, and works only on comments you authored. Adds an |
edit_post | write | Replace the body text of one of your own self-text posts. Mutating and idempotent (same text → same result); it overwrites the previous body. Requires REDDIT_USERNAME and REDDIT_PASSWORD, and works only on self posts you authored — titles and link posts cannot be edited. Adds an |
get_me | read | Get the authenticated user |
get_more_comments | read | Expand truncated |
get_my_overview | read | Get the authenticated user |
get_my_saved | read | Get the authenticated user |
get_post_comments | write | Get the comment thread for a post (by post id + subreddit), sorted best/top/new/controversial/old/qa. Read-only; requires OAuth credentials. Returns the post header plus threaded comments (author, OP/edited badges, score, body, nesting depth) up to |
get_post_flairs | write | List a subreddit |
get_subreddit_info | read | Get a subreddit |
get_subreddit_rules | read | Get a subreddit |
get_top_posts | read | Get the top-scoring posts from a subreddit — or from the authenticated home feed if no subreddit is given — within a time window (hour...all). Read-only; works without credentials via RSS fallback (titles and links only, no scores or comment counts). Returns a page of posts plus an |
get_trending_subreddits | read | Get the subreddits Reddit is currently featuring as trending/popular. Read-only, no parameters; requires OAuth credentials. Returns a list of subreddit names that changes through the day (cached briefly server-side). To find subreddits by keyword instead of by trend, use search_reddit with type= |
get_user_comments | read | Get comments made by a specific user, with sort (new/hot/top) and time filter. Read-only; requires OAuth credentials. Returns a page of comments (subreddit, parent post title, body excerpt, score, permalink) plus an |
get_user_posts | read | Get posts submitted by a specific user, with sort (new/hot/top) and time filter. Read-only; requires OAuth credentials. Returns a page of posts (title, subreddit, score, upvote ratio, comment count, permalink) plus an |
programming | read | A subreddit for programming |
search_reddit | read | Search Reddit for posts — or subreddits/users via |
unsave_content | destructive | Remove a post or comment from your saved items (undoes save_content). Mutating but idempotent — unsaving an item that isn |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (3 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (16)
Browse a subreddit — or the authenticated home feed when no subreddit is given — by sort order: hot, new, top, rising, or controversial. Read-only; works without credentials via RSS fallback (titles a
Get the comment thread for a post (by post id + subreddit), sorted best/top/new/controversial/old/qa. Read-only; requires OAuth credentials. Returns the post header plus threaded comments (author, OP/
Get the top-scoring posts from a subreddit — or from the authenticated home feed if no subreddit is given — within a time window (hour...all). Read-only; works without credentials via RSS fallback (ti
Get the subreddits Reddit is currently featuring as trending/popular. Read-only, no parameters; requires OAuth credentials. Returns a list of subreddit names that changes through the day (cached brief
Get comments made by a specific user, with sort (new/hot/top) and time filter. Read-only; requires OAuth credentials. Returns a page of comments (subreddit, parent post title, body excerpt, score, per
unsave_content
.env.test
.prettierignore
import type { RedditClientConfig } from "../../types"const result = await client.getUser("../../api/v1/me")import type { RedditClientConfig } from "../../types"const result = await client.fetchSubredditPosts("../../api/v1/me", "hot")import type { RedditComment, RedditPost } from "../../types"dotenv, fast-xml-parser, fastmcp, functype, zod, @types/node, ajv-cli, cross-env
mcp-publisher
**Full access (OAuth):**
Gates applied: no_behavioural_pass.
375fc8c78f5ffull audit observations/trust-audit/mcp-server/jordanburke__reddit-6.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 375fc8c78f5f | BLOCK | D | 69 | first audit |
Questions
What is the Reddit MCP server?
⚙️ A Model Context Protocol (MCP) that provides tools for fetching and creating Reddit content
What tools does Reddit expose?
19 in total: 13 read-only, 5 that write, and 1 that can delete or overwrite (unsave_content). Every one is listed on this page with its risk.
Is Reddit safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 5 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Reddit need?
It reads OAUTH_ENABLED, OAUTH_TOKEN, REDDIT_AUTH_MODE, REDDIT_CLIENT_SECRET and REDDIT_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Reddit run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as reddit-mcp-server at 1.6.3.
How current is this page?
The grade is for one exact copy of the source (375fc8c78f5f), read on 2026-10-06. The repository is watched and re-audited when it changes.