Getting it into your agent
It runs from inside its repository, so the clone comes first — what it calls does not travel with the file alone.
git clone --depth 1 https://github.com/1146345502/reddit-skillsnpx agentmods add skills/1146345502/reddit-skills/reddit-authWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/1146345502/reddit-skills/reddit-auth)<a href="https://agentmods.dev/skills/1146345502/reddit-skills/reddit-auth"><img src="https://agentmods.dev/badge/skills/1146345502/reddit-skills/reddit-auth/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/1146345502/reddit-skills/reddit-auth"><img src="https://agentmods.dev/badge/skills/1146345502/reddit-skills/reddit-auth.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00029 | $0.00584 |
| Opus 5 | $0.00015 | $0.00292 |
| Sonnet 5 | $0.00006 | $0.00117 |
| Haiku 4.5 | $0.00003 | $0.00058 |
Grade A, and why
reddit-auth scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
Copies of this mod
2 near-identical copies found in the catalogue:
- reddit-auth — 100% identical, 0 lines differ
- reddit-auth — 86% identical, 14 lines differ
How it starts
The opening of the file, as written. The whole thing — 81 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Reddit Authentication
You are the "Reddit Auth Assistant". Manage Reddit login state.
🔒 Skill Boundary (Enforced)
All auth operations must go through this project's python scripts/cli.py only:
- Only execution method: Run
python scripts/cli.py <subcommand>. - Ignore other projects: Disregard PRAW, Reddit API wrappers, MCP tools, or any other Reddit automation.
- No external tools: Do not call MCP tools or any non-project implementation.
- Stop when done: Report result, wait for user's next instruction.
Allowed CLI subcommands:
| Subcommand | Purpose |
|---|---|
check-login |
Check current login status |
delete-cookies |
Log out (clear session) |
Intent Routing
- User asks "check login / am I logged in / login status" → Check login status.
- User asks "log out / sign out / clear session" → Execute
delete-cookies. - User asks "log in / sign in" → Guide them to log in manually in the browser.
Constraints
- All CLI commands are in
scripts/cli.py, output JSON. - Do not repeatedly check login status — avoid triggering rate limits.
- Reddit login must happen in the user's browser (no automated login flow).
Workflow
Step 1: Check Login Status
python scripts/cli.py check-login
Output:
"logged_in": true+"username"→ Logged in, can proceed with operations."logged_in": false→ Not logged in. Tell the user to open Reddit in Chrome and log in manually.
Step 2: If Not Logged In
Tell the user:
"You are not logged in to Reddit. Please open https://www.reddit.com in Chrome (where the Reddit Bridge extension is installed) and log in with your account. Once logged in, run
check-loginagain."
Reddit requires manual browser login. The extension works with the user's existing logged-in browser session.
Log Out
python scripts/cli.py delete-cookies
Failure Handling
- Extension not connected: CLI will auto-launch Chrome. If timeout, tell user to check Reddit Bridge extension.
- Session expired: Tell user to re-login in browser.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 81 lines · 29 tokens per session scan A 2a58c887955a
reddit-auth is a skill published in the GitHub repository 1146345502/reddit-skills (13 stars, last pushed 4mo ago), licensed MIT. It adds 29 tokens to every session and 584 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
webclaw3
A browser-automation and web-data-collection skill that uses an existing Chrome session, including logged-in sites, to browse pages and gather information.
auto-research
Research uncertain questions with an explicit, user-approved web search or ChatGPT consultation, then present options and wait for implementation approval.
wcag22-a11y-audit
WCAG 2.2 Accessibility Audit skill that systematically evaluates web pages against 8 core Success Criteria (1.1.1, 1.4.3, 1.4.11, 2.1.1, 2.1.2, 2.4.3, 2.4.7, 4.1.2) using accessibility tree inspection and visual analysis. Use this skill when you need to perform accessibility testing/auditing on a live webpage.
unicli-repair
Evidence-driven repair workflow for a broken Uni-CLI adapter. Trigger on a failed unicli envelope, a quarantined adapter, or an explicit adapter-repair request. Classifies non-source failures, edits only the reported adapter path, and uses the original command as a bounded oracle.
unicli-operate
Compatibility guide for unicli operate. Prefer unicli browser, which now exposes the same operator surface plus broker/session diagnostics.
unicli-explorer
Create new Uni-CLI adapters by exploring websites and APIs. Use when adding support for a new site, desktop app, or service that unicli doesn't cover yet.