Reddit BuddySAFE
Clean, LLM-optimized Reddit MCP server. Browse posts, search content, analyze users. No fluff, just Reddit data.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Reddit Browser for Claude Desktop and AI Assistants
A Model Context Protocol (MCP) server that enables Claude Desktop and other AI assistants to browse Reddit, search posts, and analyze user activity. Clean, fast, and actually works - browse subreddits with no API keys; add free Reddit credentials for search, comments, user analysis, and full metrics.
[](https://www.npmjs.com/package/reddit-mcp-buddy) [](https://www.npmjs.com/package/reddit-mcp-buddy) [](https://github.com/karanb192/reddit-mcp-buddy/stargazers) [](https://opensource.org/licenses/MIT)
🎬 See It In Action
Claude checking Reddit's reaction to the Dune Part Three trailer and whether the AirPods Max 2 are worth $549
Claude analyzing real-time sentiment about H-1B visa changes across r/cscareerquestions and r/india
Table of Contents
- What makes Reddit MCP Buddy different?
- Quick Start
- What can it do?
- Available Tools
- Authentication
- Installation Options
- Global Install
- From Source
- Using Docker
- Claude Desktop Extension
- [Comparison with Other Tools](#compari
ce190e31eaf4OBSERVED · 2026-09-27Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add reddit-mcp-buddy -- npx -y [email protected]
Exposed tools (5)
4 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
browse_subreddit | read | Fetch posts from a subreddit sorted by your choice (hot/new/top/rising/controversial). Returns a post list with content, metadata, and a data_source field. With Reddit credentials (data_source |
get_post_details | write | Fetch a Reddit post with its comments. Requires EITHER url OR post_id. IMPORTANT: When using post_id alone, an extra API call is made to fetch the subreddit first (2 calls total). For better efficiency, always provide the subreddit parameter when known (1 call total). |
reddit_explain | read | Get explanations of Reddit terms, slang, and culture. Returns definition, origin, usage, and examples. |
search_reddit | read | Search for posts across Reddit or specific subreddits. Returns matching posts with content and metadata. |
user_analysis | read | Analyze a Reddit user\ |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (7 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (10)
.mcpignore
const badSubs = ["../../api/v1/me", "programming/../../user/spez/about.json", "x?limit=1",
"prog/hot.json?x=", "a".repeat(50), "../../../", "sub reddit", "", "a/b",
const t2 = !userAnalysisSchema.safeParse({ username: "../../api/v1/me" }).successconst t3 = !getPostDetailsSchema.safeParse({ post_id: "../../x" }).success;const t4 = !searchRedditSchema.safeParse({ query: "x", subreddits: ["ok", "../../api/v1/me"] }).success;@modelcontextprotocol/sdk, zod, zod-to-json-schema, @types/node, @typescript-eslint/eslint-plugin, @typescript-eslint/parser, eslint, tsx
assets/images/reddit-mcp-buddy.gif
assets/reddit-mcp-buddy-icon-white-background.png
assets/reddit-mcp-buddy-icon.png
Gates applied: no_behavioural_pass.
ce190e31eaf4full audit observations/trust-audit/mcp-server/karanb192__reddit-buddy-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-27 | ce190e31eaf4 | SAFE | B | 89 | first audit |
Questions
What is the Reddit Buddy MCP server?
Clean, LLM-optimized Reddit MCP server. Browse posts, search content, analyze users. No fluff, just Reddit data.
What tools does Reddit Buddy expose?
5 in total: 4 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Reddit Buddy safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Reddit Buddy need?
It reads REDDIT_CLIENT_SECRET and REDDIT_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Reddit Buddy run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as reddit-mcp-buddy at 1.1.14.
How current is this page?
The grade is for one exact copy of the source (ce190e31eaf4), read on 2026-09-27. The repository is watched and re-audited when it changes.