RedditBLOCK
🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Browse, search, post to, and moderate any subreddit from your agent.
Quick Start
Read-only (no setup needed):
node scripts/reddit.mjs posts news --limit 5 node scripts/reddit.mjs search all "breaking news"
Posting & Moderation (requires OAuth):
- Create a Reddit app at https://www.reddit.com/prefs/apps
- Set environment variables (see Setup below)
- Run
node scripts/reddit.mjs loginonce to authorize
Setup for Posting/Moderation
1. Create a Reddit App
- Go to https://www.reddit.com/prefs/apps
- Scroll down and click "create another app..."
- Fill in:
- name: anything (e.g., "clawdbot")
- type: select script
- redirect uri:
http://localhost:8080/callback - Click Create app
- Note your:
- Client ID — the string under your app name
- Client Secret — labeled "secret"
2. Set Environment Variables
Add these to your shell profile or Clawdbot's environment:
export REDDIT_CLIENT_ID="your_client_id" export REDDIT_CLIENT_SECRET="your_client_secret" export REDDIT_USERNAME="your_reddit_username" export REDDIT_PASSWORD="your_reddit_password"
3. Authorize (One Time)
node scripts/reddit.mjs login
This opens a browser for OAuth. After authorizing, a token is saved to ~/.reddit-token.json and auto-refreshes.
Personalizing the Skill
The SKILL.md file tells your agent how to use this skill. You'll want to customize it for your setup:
Update the Examples
Replace the generic subreddit names (wallstreetbets, yoursubreddit) with the ones you actually use:
# Before
node {baseDir}/scripts/reddit.mjs posts wallstreetbets
# After
node {baseDir}/scripts/reddit.mjs posts mysubredditAdd Your Subreddits to the Notes
At the bottom of SKILL.md, add a section listing your subreddits:
## My Subreddits - **r/mysubreddit** — I'm a mod here (full access) - **r/interestingtopic
4f3b4a2a472eOBSERVED · 2026-10-08Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| openclaw | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
---
name: reddit
description: Browse, search, post, and moderate Reddit. Read-only works without auth; posting/moderation requires OAuth setup.
metadata: {"clawdbot":{"emoji":"📣","requires":{"bins":["node"]}}}
---
# Reddit
Browse, search, post to, and moderate subreddits. Read-only actions work without auth; posting/moderation requires OAuth setup.
## Setup (for posting/moderation)
1. Go to https://www.reddit.com/prefs/apps
2. Click "create another app..."
3. Select "script" type
4. Set redirect URI to `http://localhost:8080`
5. Note your client ID (under app name) and client secret
6. Set environment variables:
```bash
export REDDIT_CLIENT_ID="your_client_id"
export REDDIT_CLIENT_SECRET="your_client_secret"
export REDDIT_USERNAME="your_username"
export REDDIT_PASSWORD="your_password"
```
## Read Posts (no auth required)
```bash
# Hot posts from a subreddit
node {baseDir}/scripts/reddit.mjs posts wallstreetbets
# New posts
node {baseDir}/scripts/reddit.mjs posts wallstreetbets --sort new
# Top posts (day/week/month/year/all)
node {baseDir}/scripts/reddit.mjs posts wallstreetbets --sort top --time week
# Limit results
node {baseDir}/scripts/reddit.mjs posts wallstreetbets --limit 5
```
## Search Posts
```bash
# Search within a subreddit
node {baseDir}/scripts/reddit.mjs search wallstreetbets "YOLO"
# Search all of Reddit
node {baseDir}/scripts/reddit.mjs search all "stock picks"
```
## Get Comments on a Post
```bash
# By post ID or full URL
node {baseDir}/scripts/reddit.mjs comments POST_ID
node {baseDir}/scripts/reddit.mjs comments "https://reddit.com/r/subreddit/comments/abc123/..."
```
## Submit a Post (requires auth)
```bash
# Text post
node {baseDir}/scripts/reddit.mjs submit yoursubreddit --title "Weekly Discussion" --text "What's on your mind?"
# Link post
node {baseDir}/scripts/reddit.mjs submit yoursubreddit --title "Great article" --url "https://example.com/article"
```
## Reply to a Post/Comment (requires auth)
```bash
node {baseDir}/scripts/reddit.mjs reply THING_ID "Your reply text here"
```
## Moderation (requires auth + mod permissions)
```bash
# Remove a post/comment
node {baseDir}/scripts/reddit.mjs mod remove THING_ID
# Approve a post/comment
node {baseDir}/scripts/reddit.mjs mod approve THING_ID
# Sticky a post
node {baseDir}/scripts/reddit.mjs mod sticky POST_ID
# Unsticky
node {baseDir}/scripts/reddit.mjs mod unsticky POST_ID
# Lock comments
node {baseDir}/scripts/reddit.mjs mod lock POST_ID
# View modqueue
node {baseDir}/scripts/reddit.mjs mod queue yoursubreddit
```
## Notes
- Read actions use Reddit's public JSON API (no auth needed)
- Post/mod actions require OAuth - run `login` command once to authorize
- Token stored at `~/.reddit-token.json` (auto-refreshes)
- Rate limits: ~60 requests/minute for OAuth, ~10/minute for unauthenticatedTrust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (4 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (3)
exec(`${cmd} "${authUrl}"`);<key>k5Ey9KFlkqpj+SDkUw+5ED9lTA3En/qUi0zdrydUCH3kMWTE3Eh65NXnFCaxlY2omY2JHnlEoK7Li7oOEvM7eG5VPdcO/sFlMfoCRdnLYdepJ+uLzYwOWR8W4yQVve/clxVFTVRL4DFleKInGdpAxIbHZT2yi4ADAMENls1N1XSLojRuqXePXDeAT/4Mv4TTx0s
- **r/mysubreddit** — I'm a mod here (full access)
Gates applied: no_behavioural_pass.
4f3b4a2a472efull audit observations/trust-audit/skill/leoyeai__reddit.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 4f3b4a2a472e | BLOCK | D | 69 | first audit |
Questions
What does the Reddit skill do?
🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai
Is Reddit safe to install?
No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What can Reddit access on my machine?
The audit observed that it reaches the network and runs shell commands. Each of those is consistent with what it says it does. Secrets in the source: none found.
What do I need installed to use Reddit?
Its own instructions reference login. Dependencies are pinned to exact versions.
Which assistants does Reddit work with?
Its documentation mentions openclaw. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (4f3b4a2a472e), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.