T03 · Remote Payload Retrieval and Execution
- Location
agent_reach/cli.py:374- Finding
Unverified NodeSource Shell Script Is Downloaded and Executed
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill matches its web-research purpose, but setup can automatically copy browser login cookies and install mutable external tools without strong user confirmation.
Install only after reviewing the setup path. Prefer safe or dry-run mode, avoid automatic browser-cookie import unless you intentionally want this tool to read active sessions, and treat any copied cookies as account credentials. Be cautious with the unpinned global installs, Docker/MCP services, and remote setup/update instructions.
agent_reach/cli.py:374Unverified NodeSource Shell Script Is Downloaded and Executed
agent_reach/cli.py:506Mutable Third-Party GitHub Repository Is Cloned and Its Python Code Is Executed
agent_reach/cli.py:196Default Installation Automatically Extracts Browser Authentication Cookies
agent_reach/cli.py:399Installer Automatically Installs Unpinned Global and System Python Dependencies
SKILL.md:165Skill Delegates Setup to Mutable Remote Instructions
agent_reach/cli.py:1217Update Guidance Installs Executable Code Directly from a Mutable Development Branch
If the underlying skill accesses browser cookie stores or uses harvested session material to configure channels, that is highly sensitive behavior not disclosed in the top-level description. In this context, the guide already instructs cookie import and browser-derived cookie use, so undisclosed credential acquisition would significantly elevate risk beyond ordinary web search.
If the underlying skill accesses browser cookie stores or uses harvested session material to configure channels, that is highly sensitive behavior not disclosed in the top-level description. In this context, the guide already instructs cookie import and browser-derived cookie use, so undisclosed credential acquisition would significantly elevate risk beyond ordinary web search.
If the underlying skill accesses browser cookie stores or uses harvested session material to configure channels, that is highly sensitive behavior not disclosed in the top-level description. In this context, the guide already instructs cookie import and browser-derived cookie use, so undisclosed credential acquisition would significantly elevate risk beyond ordinary web search.
If the underlying skill accesses browser cookie stores or uses harvested session material to configure channels, that is highly sensitive behavior not disclosed in the top-level description. In this context, the guide already instructs cookie import and browser-derived cookie use, so undisclosed credential acquisition would significantly elevate risk beyond ordinary web search.
If the underlying skill accesses browser cookie stores or uses harvested session material to configure channels, that is highly sensitive behavior not disclosed in the top-level description. In this context, the guide already instructs cookie import and browser-derived cookie use, so undisclosed credential acquisition would significantly elevate risk beyond ordinary web search.
If the underlying skill accesses browser cookie stores or uses harvested session material to configure channels, that is highly sensitive behavior not disclosed in the top-level description. In this context, the guide already instructs cookie import and browser-derived cookie use, so undisclosed credential acquisition would significantly elevate risk beyond ordinary web search.
If the underlying skill accesses browser cookie stores or uses harvested session material to configure channels, that is highly sensitive behavior not disclosed in the top-level description. In this context, the guide already instructs cookie import and browser-derived cookie use, so undisclosed credential acquisition would significantly elevate risk beyond ordinary web search.
The documentation explicitly suggests --cookies-from-browser chrome, which reads authentication cookies from a local browser profile. In a multi-platform web skill, normalizing browser-cookie extraction is dangerous because it can expose active sessions and effectively acts like credential harvesting even if framed as a convenience workaround.
yt-dlp --dump-json "ytsearch5:query" # search
## Bilibili (yt-dlp)
```bash
yt-dlp --dump-json "https://www.bilibili.com/video/BVxxx"
yt-dlp --write-sub --write-auto-sub --sub-lang "zh-Hans,zh,en" --convert-subs vtt --skip-download -o "/tmp/%(id)s" "URL"
Server IPs may get 412. Use
--cookies-from-browser chromeor configure proxy.
curl -s "https://www.reddit.com/r/SUBREDDIT/hot.json?limit=10" -H "User-Agent: agent-reach/1.0"
curl -s "https://www.reddit.com/search.json?q=QUERY&limit=10" -H "User-Agent: agent-reach/1.0"
Server IPs may get 403. Search via Exa instead, or configure proxy.
gh search repos "query" --sort stars --limit 10
gh repo view owner/repo
gh search code "query" --language python
gh issue list -R owner/repo --state open
gh issue view 123 -R owner/repo
The guide explicitly instructs use of a tool to bypass WeChat anti-bot protections in order to read content. Bypass guidance increases legal, compliance, and abuse risk, and normalizes evasion techniques that can be repurposed beyond the stated research use case.
The CLI advertises auto-extracting all supported platform cookies from local browsers, which is highly sensitive credential access and exceeds the narrow expectation of a web search/read tool. In this skill context, broad browser-cookie harvesting is especially dangerous because those cookies can enable authenticated access across multiple platforms.
The skill explicitly supports extracting all platform cookies from browsers, which matches credential-stealer behavior even if intended for convenience. In a multi-platform agent skill, that capability is especially dangerous because it centralizes authenticated sessions from several services into one tool.
"twitter-cookies", "youtube-cookies"],
help="What to configure (omit if using --from-browser)")
p_conf.add_argument("value", nargs="*", help="The value(s) to set")
p_conf.add_argument("--from-browser", metavar="BROWSER",
choices=["chrome", "firefox", "edge", "brave", "opera"],
help="Auto-extract ALL platform cookies from browser (chrome/firefox/edge/brave/opera)")
# ── doctor ──
sub.add_parser("doctor", help="Check platform availability")
# ── uninstall ──
p_uninstall = sub.add_parser("uninstall", help="Remove all Agent Reach config, tokens, and skill files")
p_uninstall.add_argument("--dry-run", action="store_true",
help="Show what would be removed without making any changes")
p_uninstall.add_argument("--keep-config", action="store_true",
help="Remove skill files only, keep ~/.agent-reach
This block installs packages, downloads remote artifacts, executes a fetched script, writes repo configuration, and modifies global runtimes on the host system. Given the skill's search/read framing, these privileged bootstrap actions materially raise the chance of arbitrary code execution, supply-chain compromise, and unauthorized persistence.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
if os_type == "linux":
try:
# Official GitHub apt source setup without invoking a shell.
keyring_path = "/usr/share/keyrings/githubcli-archive-keyring.gpg"
list_path = "/etc/apt/sources.list.d/github-cli.list"
arch = subprocess.run(
["dpkg", "--print-architecture"],
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
if os_type == "linux":
try:
# Official GitHub apt source setup without invoking a shell.
keyring_path = "/usr/share/keyrings/githubcli-archive-keyring.gpg"
list_path = "/etc/apt/sources.list.d/github-cli.list"
arch = subprocess.run(
["dpkg", "--print-architecture"],
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
if os_type == "linux":
try:
# Official GitHub apt source setup without invoking a shell.
keyring_path = "/usr/share/keyrings/githubcli-archive-keyring.gpg"
list_path = "/etc/apt/sources.list.d/github-cli.list"
arch = subprocess.run(
["dpkg", "--print-architecture"],
The installer clones and depends on a third-party WeChat repository unrelated to core search/read tasks, expanding both attack surface and trust boundaries. This is dangerous because it silently imports external code into a credential-aware environment.
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
def _install_system_deps_safe():
"""Safe mode: check what's installed, print instructions for what's missing."""
import shutil
print("Checking system dependencies (safe mode — no auto-install)...")
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
def _install_system_deps_safe():
"""Safe mode: check what's installed, print instructions for what's missing."""
import shutil
print("Checking system dependencies (safe mode — no auto-install)...")
Even in dry-run/help output, recommending curl ... | bash normalizes unsafe installation practices that execute remote scripts directly. For a broadly distributed skill, this increases the chance users follow dangerous bootstrap steps.
checks = [
("gh CLI", ["gh"], "apt install gh / brew install gh"),
("Node.js", ["node"], "curl NodeSource setup | bash + apt install nodejs"),
("xreach CLI", ["xreach"], "npm install -g xreach-cli"),
]
The printed guidance suggests a remote script piped to bash for Node installation via fnm, which is a classic unsafe bootstrap pattern. While not executed by this line, it still steers users toward risky remote code execution.
# Check for npm/npx
if not shutil.which("npm") and not shutil.which("npx"):
print(" [!] mcporter requires Node.js. Install Node.js first:")
print(" https://nodejs.org/ or: curl -fsSL https://fnm.vercel.app/install | bash")
return
try:
subprocess.run(
Copying the full parent environment and then invoking an external binary while adding sensitive Twitter tokens expands the secret exposure surface. Unrelated inherited environment variables may also be passed downstream, and the external CLI gains access to both harvested cookies and the entire execution context.
print("[!] xreach CLI not installed. Run: npm install -g xreach-cli")
else:
import os
env = os.environ.copy()
env["AUTH_TOKEN"] = auth_token
env["CT0"] = ct0
result = subprocess.run(
The update command recommends pip install --upgrade directly from a GitHub archive URL on the main branch, which is mutable and bypasses stronger packaging controls. This creates a remote bootstrap path where a compromised repo or branch can deliver arbitrary code to users.
_version__:
print(f"最新版本: v{latest} ← 有更新!")
if body:
print()
print("更新内容:")
# Show first 20 lines of release notes
for line in body.strip().split("\n")[:20]:
print(f" {line}")
print()
print("更新命令:")
print(" pip install --upgrade https://github.com/Panniantong/agent-reach/archive/main.zip")
return "update_available"
print(f"✅ 已是最新版本")
return "up_to_date"
release_err = _classify_github_response_error(resp)
if release_err == "rate_limit":
print("[!] 无法检查更新(GitHub API 速率限制,请稍后重试)")
return "error"
# No releases yet, fall back to latest main commit.
resp2, err2, attempts2 = _github_get_with_retry(commit_url, timeout=10, retries=2)
if err2:
print(f"[!] 无法检查更�
The module advertises automatic extraction of browser cookies from multiple browsers and platforms but provides no user-facing warning that it is accessing highly sensitive session data. In this skill context, that is especially risky because users may expect web research functionality, not local credential harvesting, so the absence of clear disclosure can lead to silent collection of authentication material.
This code extracts live authentication cookies such as Twitter auth_token/ct0 and Bilibili SESSDATA/bili_jct from local browser storage. Those values are effectively session credentials; anyone who obtains or misuses them can impersonate the user on external services without knowing the password, making this a direct credential-access issue.
The code writes extracted session cookies directly into persistent configuration keys without any visible confirmation, secrecy controls, or user approval at the time of storage. Persisting raw session tokens increases the blast radius of compromise because any later read of the config, logs, backups, or debugging output could expose credentials that enable account takeover.
No suspicious patterns detected.