Back to skill

Security audit

Agent Reach

Security checks for vulnerabilities and agentic risk

Overview

This skill is a broad internet and platform automation guide, but it gives agents under-scoped authority around cookies, account actions, persistent storage, and mutable setup instructions.

Review this skill before installing. It is best used only with explicit user control: avoid giving raw cookies or allowing browser-cookie extraction unless absolutely necessary, confirm any posting or account-changing action before it happens, and prefer a sandbox or dedicated platform accounts for setup and testing.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:159
Finding

Unpinned Global Dependency and Mutable Remote Setup Instructions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 159–166
Vulnerability Type: Supply-chain exposure through an unpinned global package installation and mutable remote instructions
Risk Level: Medium

markdown
- **Twitter fetch failed?** Ensure `undici` is installed: `npm install -g undici`. Configure proxy: `agent-reach configure proxy URL`.

## Setting Up a Channel ("帮我配 XXX")

If a channel needs setup (cookies, Docker, etc.), fetch the install guide:
https://raw.githubusercontent.com/Panniantong/agent-reach/main/docs/install.md

User only provides cookies. Everything else is your job.

Technical Analysis

The troubleshooting instructions install the latest available version of undici globally without a fixed version, lockfile, or integrity verification. Package installation can execute package lifecycle logic and places files in a globally accessible tool location. Consequently, the behavior installed at execution time is not necessarily the behavior that existed when this Skill was reviewed.

The setup workflow also directs the agent to retrieve instructions from the mutable main branch of an external GitHub repository and broadly instructs it to perform all setup work. The retrieved document is not part of this audited project, is not pinned to a reviewed commit, and can change independently. Although the audited file does not itself explicitly execute a downloaded payload, following subsequently modified setup instructions could cause the agent to install or run unaudited components.

Attack Path

  1. An attacker compromises the relevant npm package publication path, dependency resolution path, GitHub repository, or maintainer account.
  2. The attacker publishes a malicious package release or modifies docs/install.md on the mutable main branch to include unsafe installation or execution steps.
  3. A user encounters a Twitter-channel failure or requests configuration of a supported cha ...[truncated 983 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin undici to a specifically reviewed version rather than installing the latest release.
  • Use a project-local dependency manifest and lockfile instead of a global npm installation.
  • Verify dependency integrity with trusted registry metadata and lockfile integrity hashes.
  • Disable or strictly control package lifecycle scripts where they are not required.
  • Pin the installation guide to a reviewed commit hash instead of the mutable main branch.
  • Vendor reviewed setup instructions into the Skill package so that audited behavior cannot change remotely.
  • Require explicit user confirmation before installing software, starting containers, importing cookies, or executing commands obtained from external documentation.
  • Restrict setup operations to a sandbox or least-privileged environment and avoid exposing unrelated credentials or user files.
  • Re-review and update pinned dependencies and documentation through a controlled release process.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (7)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger list contains very broad everyday phrases such as 'research', 'find information', and '帮我查', which can cause the skill to activate for many unrelated requests. Because this skill has network access and can perform external interactions, overbroad invocation increases the chance of unintended browsing, data handling, or platform actions without clear user intent.

Content

No source excerpt is available for this finding.

YARA rule 'info_stealer': Information stealer patterns (credential harvesting, browser data theft) [malware]

High
Category
YARA Match
Confidence
84% confidence
Finding

The instruction to use '--cookies-from-browser chrome' tells the agent to extract authentication cookies directly from a local browser profile. Even if presented as a convenience for accessing a site, this pattern is dangerous because it accesses highly sensitive session material that can authenticate the user to external services and resembles credential-harvesting behavior.

Content

Scanner excerpt · SKILL.md (reported line 73)May include surrounding context.

L" # download subtitles, then read the .vtt file yt-dlp --dump-json "ytsearch5:query" # search

text

## Bilibili (yt-dlp)

```bash
yt-dlp --dump-json "https://www.bilibili.com/video/BVxxx"
yt-dlp --write-sub --write-auto-sub --sub-lang "zh-Hans,zh,en" --convert-subs vtt --skip-download -o "/tmp/%(id)s" "URL"

Server IPs may get 412. Use --cookies-from-browser chrome or configure proxy.

Reddit

bash
curl -s "https://www.reddit.com/r/SUBREDDIT/hot.json?limit=10" -H "User-Agent: agent-reach/1.0"
curl -s "https://www.reddit.com/search.json?q=QUERY&limit=10" -H "User-Agent: agent-reach/1.0"

Server IPs may get 403. Search via Exa instead, or configure proxy.

GitHub (gh CLI)

bash
gh search repos "query" --sort stars --limit 10
gh repo view owner/repo
gh search code "query" --language python
gh issue list -R owner/repo --state open
gh issue view 123 -R owner/repo

小红书 / XiaoHongShu (mcporter)

bas

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description explicitly says the skill should be used when users ask to 'post, comment, or interact on supported platforms', but it does not require explicit confirmation or warn that these actions can make external changes. A skill that can transition from read/search behavior to write/interaction behavior without prominent safeguards risks accidental posting or unwanted account actions.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
82% confidence
Finding

The skill directs the agent to use '~/.agent-reach/' for persistent data, creating a standing storage location outside the workspace. Persistent storage is risky in an agent context because it can retain browsing artifacts, tokens, cookies, logs, or other sensitive material across sessions, expanding the blast radius of any mistake or compromise.

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

md
## ⚠️ Workspace Rules

**Never create files in the agent workspace.** Use `/tmp/` for temporary output and `~/.agent-reach/` for persistent data.

## Web — Any URL

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The setup guidance states that 'User only provides cookies. Everything else is your job,' which normalizes collection and handling of sensitive session credentials without any privacy, scope, storage, or disposal constraints. Cookies can grant full account access, so encouraging the agent to receive and use them materially raises the risk of credential exposure, misuse, or persistence beyond user intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The command explicitly requests subtitles in "zh-Hans,zh,en", imposing a fixed language priority. The markdown does not indicate that language selection is configurable or based on user preference, which can violate language/locale choice expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This example fixes subtitle language selection to "zh-Hans,zh,en" rather than offering language selection based on the user's preference. Without documented opt-in or justification, this is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.