Back to skill

Security audit

Agent Reach.Skip

Security checks for vulnerabilities and agentic risk

Overview

This skill matches its web-research purpose, but setup can automatically copy browser login cookies and install mutable external tools without strong user confirmation.

Install only after reviewing the setup path. Prefer safe or dry-run mode, avoid automatic browser-cookie import unless you intentionally want this tool to read active sessions, and treat any copied cookies as account credentials. Be cautious with the unpinned global installs, Docker/MCP services, and remote setup/update instructions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (6)

T03 · Remote Payload Retrieval and Execution

Error
Location
agent_reach/cli.py:374
Finding

Unverified NodeSource Shell Script Is Downloaded and Executed

Content
View full analysis
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
agent_reach/cli.py:506
Finding

Mutable Third-Party GitHub Repository Is Cloned and Its Python Code Is Executed

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
agent_reach/cli.py:196
Finding

Default Installation Automatically Extracts Browser Authentication Cookies

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
agent_reach/cli.py:399
Finding

Installer Automatically Installs Unpinned Global and System Python Dependencies

Content
View full analysis
Remediation
View remediation

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:165
Finding

Skill Delegates Setup to Mutable Remote Instructions

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
agent_reach/cli.py:1217
Finding

Update Guidance Installs Executable Code Directly from a Mutable Development Branch

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
Findings (132)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the underlying skill accesses browser cookie stores or uses harvested session material to configure channels, that is highly sensitive behavior not disclosed in the top-level description. In this context, the guide already instructs cookie import and browser-derived cookie use, so undisclosed credential acquisition would significantly elevate risk beyond ordinary web search.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the underlying skill accesses browser cookie stores or uses harvested session material to configure channels, that is highly sensitive behavior not disclosed in the top-level description. In this context, the guide already instructs cookie import and browser-derived cookie use, so undisclosed credential acquisition would significantly elevate risk beyond ordinary web search.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the underlying skill accesses browser cookie stores or uses harvested session material to configure channels, that is highly sensitive behavior not disclosed in the top-level description. In this context, the guide already instructs cookie import and browser-derived cookie use, so undisclosed credential acquisition would significantly elevate risk beyond ordinary web search.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

If the underlying skill accesses browser cookie stores or uses harvested session material to configure channels, that is highly sensitive behavior not disclosed in the top-level description. In this context, the guide already instructs cookie import and browser-derived cookie use, so undisclosed credential acquisition would significantly elevate risk beyond ordinary web search.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the underlying skill accesses browser cookie stores or uses harvested session material to configure channels, that is highly sensitive behavior not disclosed in the top-level description. In this context, the guide already instructs cookie import and browser-derived cookie use, so undisclosed credential acquisition would significantly elevate risk beyond ordinary web search.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the underlying skill accesses browser cookie stores or uses harvested session material to configure channels, that is highly sensitive behavior not disclosed in the top-level description. In this context, the guide already instructs cookie import and browser-derived cookie use, so undisclosed credential acquisition would significantly elevate risk beyond ordinary web search.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the underlying skill accesses browser cookie stores or uses harvested session material to configure channels, that is highly sensitive behavior not disclosed in the top-level description. In this context, the guide already instructs cookie import and browser-derived cookie use, so undisclosed credential acquisition would significantly elevate risk beyond ordinary web search.

Content

No source excerpt is available for this finding.

YARA rule 'info_stealer': Information stealer patterns (credential harvesting, browser data theft) [malware]

High
Category
YARA Match
Confidence
92% confidence
Finding

The documentation explicitly suggests --cookies-from-browser chrome, which reads authentication cookies from a local browser profile. In a multi-platform web skill, normalizing browser-cookie extraction is dangerous because it can expose active sessions and effectively acts like credential harvesting even if framed as a convenience workaround.

Content

Scanner excerpt · SKILL.md (reported line 68)May include surrounding context.

download subtitles, then read the .vtt file

yt-dlp --dump-json "ytsearch5:query" # search

text

## Bilibili (yt-dlp)

```bash
yt-dlp --dump-json "https://www.bilibili.com/video/BVxxx"
yt-dlp --write-sub --write-auto-sub --sub-lang "zh-Hans,zh,en" --convert-subs vtt --skip-download -o "/tmp/%(id)s" "URL"

Server IPs may get 412. Use --cookies-from-browser chrome or configure proxy.

Reddit

bash
curl -s "https://www.reddit.com/r/SUBREDDIT/hot.json?limit=10" -H "User-Agent: agent-reach/1.0"
curl -s "https://www.reddit.com/search.json?q=QUERY&limit=10" -H "User-Agent: agent-reach/1.0"

Server IPs may get 403. Search via Exa instead, or configure proxy.

GitHub (gh CLI)

bash
gh search repos "query" --sort stars --limit 10
gh repo view owner/repo
gh search code "query" --language python
gh issue list -R owner/repo --state open
gh issue view 123 -R owner/repo

小红书 / XiaoHongS

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The guide explicitly instructs use of a tool to bypass WeChat anti-bot protections in order to read content. Bypass guidance increases legal, compliance, and abuse risk, and normalizes evasion techniques that can be repurposed beyond the stated research use case.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The CLI advertises auto-extracting all supported platform cookies from local browsers, which is highly sensitive credential access and exceeds the narrow expectation of a web search/read tool. In this skill context, broad browser-cookie harvesting is especially dangerous because those cookies can enable authenticated access across multiple platforms.

Content

No source excerpt is available for this finding.

YARA rule 'info_stealer': Information stealer patterns (credential harvesting, browser data theft) [malware]

High
Category
YARA Match
Confidence
97% confidence
Finding

The skill explicitly supports extracting all platform cookies from browsers, which matches credential-stealer behavior even if intended for convenience. In a multi-platform agent skill, that capability is especially dangerous because it centralizes authenticated sessions from several services into one tool.

Content

Scanner excerpt · agent_reach/cli.py (reported line 81)May include surrounding context.

python
"twitter-cookies", "youtube-cookies"],
                        help="What to configure (omit if using --from-browser)")
    p_conf.add_argument("value", nargs="*", help="The value(s) to set")
    p_conf.add_argument("--from-browser", metavar="BROWSER",
                        choices=["chrome", "firefox", "edge", "brave", "opera"],
                        help="Auto-extract ALL platform cookies from browser (chrome/firefox/edge/brave/opera)")

    # ── doctor ──
    sub.add_parser("doctor", help="Check platform availability")

    # ── uninstall ──
    p_uninstall = sub.add_parser("uninstall", help="Remove all Agent Reach config, tokens, and skill files")
    p_uninstall.add_argument("--dry-run", action="store_true",
                             help="Show what would be removed without making any changes")
    p_uninstall.add_argument("--keep-config", action="store_true",
                             help="Remove skill files only, keep ~/.agent-reach

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This block installs packages, downloads remote artifacts, executes a fetched script, writes repo configuration, and modifies global runtimes on the host system. Given the skill's search/read framing, these privileged bootstrap actions materially raise the chance of arbitrary code execution, supply-chain compromise, and unauthorized persistence.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · agent_reach/cli.py (reported line 326)May include surrounding context.

python
if os_type == "linux":
            try:
                # Official GitHub apt source setup without invoking a shell.
                keyring_path = "/usr/share/keyrings/githubcli-archive-keyring.gpg"
                list_path = "/etc/apt/sources.list.d/github-cli.list"
                arch = subprocess.run(
                    ["dpkg", "--print-architecture"],

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · agent_reach/cli.py (reported line 333)May include surrounding context.

python
if os_type == "linux":
            try:
                # Official GitHub apt source setup without invoking a shell.
                keyring_path = "/usr/share/keyrings/githubcli-archive-keyring.gpg"
                list_path = "/etc/apt/sources.list.d/github-cli.list"
                arch = subprocess.run(
                    ["dpkg", "--print-architecture"],

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · agent_reach/cli.py (reported line 337)May include surrounding context.

python
if os_type == "linux":
            try:
                # Official GitHub apt source setup without invoking a shell.
                keyring_path = "/usr/share/keyrings/githubcli-archive-keyring.gpg"
                list_path = "/etc/apt/sources.list.d/github-cli.list"
                arch = subprocess.run(
                    ["dpkg", "--print-architecture"],

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The installer clones and depends on a third-party WeChat repository unrelated to core search/read tasks, expanding both attack surface and trust boundaries. This is dangerous because it silently imports external code into a credential-aware environment.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · agent_reach/cli.py (reported line 524)May include surrounding context.

python
def _install_system_deps_safe():
    """Safe mode: check what's installed, print instructions for what's missing."""
    import shutil

    print("Checking system dependencies (safe mode — no auto-install)...")

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · agent_reach/cli.py (reported line 685)May include surrounding context.

python
def _install_system_deps_safe():
    """Safe mode: check what's installed, print instructions for what's missing."""
    import shutil

    print("Checking system dependencies (safe mode — no auto-install)...")

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Even in dry-run/help output, recommending curl ... | bash normalizes unsafe installation practices that execute remote scripts directly. For a broadly distributed skill, this increases the chance users follow dangerous bootstrap steps.

Content

Scanner excerpt · agent_reach/cli.py (reported line 584)May include surrounding context.

python
checks = [
        ("gh CLI", ["gh"], "apt install gh / brew install gh"),
        ("Node.js", ["node"], "curl NodeSource setup | bash + apt install nodejs"),
        ("xreach CLI", ["xreach"], "npm install -g xreach-cli"),
    ]

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

The printed guidance suggests a remote script piped to bash for Node installation via fnm, which is a classic unsafe bootstrap pattern. While not executed by this line, it still steers users toward risky remote code execution.

Content

Scanner excerpt · agent_reach/cli.py (reported line 626)May include surrounding context.

python
# Check for npm/npx
        if not shutil.which("npm") and not shutil.which("npx"):
            print("  [!]  mcporter requires Node.js. Install Node.js first:")
            print("     https://nodejs.org/ or: curl -fsSL https://fnm.vercel.app/install | bash")
            return
        try:
            subprocess.run(

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
89% confidence
Finding

Copying the full parent environment and then invoking an external binary while adding sensitive Twitter tokens expands the secret exposure surface. Unrelated inherited environment variables may also be passed downstream, and the external CLI gains access to both harvested cookies and the entire execution context.

Content

Scanner excerpt · agent_reach/cli.py (reported line 857)May include surrounding context.

python
print("[!] xreach CLI not installed. Run: npm install -g xreach-cli")
                else:
                    import os
                    env = os.environ.copy()
                    env["AUTH_TOKEN"] = auth_token
                    env["CT0"] = ct0
                    result = subprocess.run(

YARA rule 'agent_skill_remote_bootstrap_execution': Remote script or code download followed by execution/bootstrap installation [agent_skills]

High
Category
YARA Match
Confidence
87% confidence
Finding

The update command recommends pip install --upgrade directly from a GitHub archive URL on the main branch, which is mutable and bypasses stronger packaging controls. This creates a remote bootstrap path where a compromised repo or branch can deliver arbitrary code to users.

Content

Scanner excerpt · agent_reach/cli.py (reported line 1217)May include surrounding context.

python
_version__:
            print(f"最新版本: v{latest} ← 有更新!")
            if body:
                print()
                print("更新内容:")
                # Show first 20 lines of release notes
                for line in body.strip().split("\n")[:20]:
                    print(f"  {line}")
            print()
            print("更新命令:")
            print("  pip install --upgrade https://github.com/Panniantong/agent-reach/archive/main.zip")
            return "update_available"
        print(f"✅ 已是最新版本")
        return "up_to_date"

    release_err = _classify_github_response_error(resp)
    if release_err == "rate_limit":
        print("[!] 无法检查更新(GitHub API 速率限制,请稍后重试)")
        return "error"

    # No releases yet, fall back to latest main commit.
    resp2, err2, attempts2 = _github_get_with_retry(commit_url, timeout=10, retries=2)
    if err2:
        print(f"[!] 无法检查更�

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The module advertises automatic extraction of browser cookies from multiple browsers and platforms but provides no user-facing warning that it is accessing highly sensitive session data. In this skill context, that is especially risky because users may expect web research functionality, not local credential harvesting, so the absence of clear disclosure can lead to silent collection of authentication material.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This code extracts live authentication cookies such as Twitter auth_token/ct0 and Bilibili SESSDATA/bili_jct from local browser storage. Those values are effectively session credentials; anyone who obtains or misuses them can impersonate the user on external services without knowing the password, making this a direct credential-access issue.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code writes extracted session cookies directly into persistent configuration keys without any visible confirmation, secrecy controls, or user approval at the time of storage. Persisting raw session tokens increases the blast radius of compromise because any later read of the config, logs, backups, or debugging output could expose credentials that enable account takeover.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.