Back to skill

Security audit

Agent Reach Setup

Security checks for vulnerabilities and agentic risk

Overview

This skill is an installer for Agent Reach, but it can automatically run an unpinned remote installer and change the user's Python and agent configuration without enough safeguards.

Review this carefully before installing. Avoid running npm install scripts for it and do not use the provided --break-system-packages command on your main Python environment. Prefer an isolated environment, a pinned and verified Agent Reach release, and manual opt-in for Exa or other MCP services. Do not paste real proxy passwords or Twitter cookies directly into command-line examples.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

T03 · Remote Payload Retrieval and Execution

Error
Location
install.sh:21
Finding

Mutable Remote Python Package Is Downloaded and Executed Without Integrity Verification

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
install.sh:23
Finding

Installer Bypasses Python System-Package Protection

Content
View full analysis
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
package.json:20
Finding

NPM Install Lifecycle Automatically Launches the Remote-Payload Installer

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
usage-examples.md:15
Finding

Proxy Credentials and Twitter Session Cookies Are Passed Through Command-Line Arguments

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
usage-examples.md:246
Finding

Predictable Shared Temporary Cache Lacks Permission and Symlink Protections

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (22)

YARA rule 'agent_skill_remote_bootstrap_execution': Remote script or code download followed by execution/bootstrap installation [agent_skills]

High
Category
YARA Match
Confidence
94% confidence
Finding

The README promotes installing and executing code directly from a remote GitHub archive on the main branch, followed by additional bootstrap commands. This is dangerous because the referenced content is mutable, unauthenticated in the command itself, and paired with environment-modifying installation steps, creating a supply-chain and remote code execution risk if the upstream repository is compromised or changed maliciously.

Content

Scanner excerpt · README.md (reported line 59)May include surrounding context.

─ troubleshooting.md # 故障排除 └── usage-examples.md # 使用示例

text

## 🔧 系统要求

- **Python**: 3.13+
- **Node.js**: 22+
- **操作系统**: Linux, macOS, Windows (WSL)
- **权限**: 用户主目录写入权限

## 📦 安装方式

### 方式1: 使用安装脚本
```bash
chmod +x install.sh
./install.sh

方式2: 手动安装

bash
# 1. 安装Agent Reach
pip install https://github.com/Panniantong/agent-reach/archive/main.zip --break-system-packages

# 2. 自动配置
agent-reach install --env=auto

# 3. 配置Exa搜索
mcporter config add exa https://mcp.exa.ai/mcp

# 4. 验证安装
agent-reach doctor

📊 配置状态

✅ 装好即用 (7/13)

  • YouTube 视频和字幕
  • RSS/Atom 订阅源
  • 全网语义搜索
  • 任意网页
  • Twitter/X 推文
  • B站视频和字幕
  • 微信公众号文章

🔧 可选配置

  • GitHub 仓库和代码
  • Reddit 帖子和评论
  • 小红书笔记
  • 抖音短视频
  • LinkedIn 职业社交
  • Boss直�

YARA rule 'agent_skill_remote_bootstrap_execution': Remote script or code download followed by execution/bootstrap installation [agent_skills]

High
Category
YARA Match
Confidence
98% confidence
Finding

The skill instructs installation directly from https://github.com/.../archive/main.zip, which fetches code from a mutable remote source and immediately installs it. In a skill document, this is especially risky because users may execute it without review; if the repository or branch contents change or are compromised, arbitrary code can be installed, and the added --break-system-packages increases host-level impact.

Content

Scanner excerpt · SKILL.md (reported line 18)May include surrounding context.

基于实际部署经验,包含问题诊断和解决方案。适用于OpenClaw、Claude Code等AI Agent环境。

核心功能

  • ✅ Agent Reach 1.3.0 完整安装
  • ✅ 7个核心渠道自动配置
  • ✅ 常见问题诊断和解决方案
  • ✅ 系统兼容性处理
  • ✅ 多环境支持(OpenClaw、Claude Code)

安装流程

步骤1: 安装Agent Reach

bash
# 解决权限问题
pip install https://github.com/Panniantong/agent-reach/archive/main.zip --break-system-packages

步骤2: 自动配置

bash
agent-reach install --env=auto

步骤3: 验证安装

bash
agent-reach doctor

步骤4: 额外配置(可选)

bash
# 配置Exa搜索
mcporter config add exa https://mcp.exa.ai/mcp

已验证的解决方案

问题1: 系统包管理限制

症状: externally-managed-environment 错误 解决方案: 使用 --break-system-packages 参数 原因: Python 3.13+ 默认启用外部包管理保护

问题2: GitHub C

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 100)May include surrounding context.

md
- `SKILL.md` - 本技能文档

YARA rule 'agent_skill_remote_bootstrap_execution': Remote script or code download followed by execution/bootstrap installation [agent_skills]

High
Category
YARA Match
Confidence
97% confidence
Finding

The script installs directly from a GitHub ZIP on the main branch, which is mutable and not pinned or integrity-checked. This is dangerous because whoever controls that repository or any compromised dependency path can change the installed code at any time, and the script immediately bootstraps it into the user's environment.

Content

Scanner excerpt · install.sh (reported line 23)May include surrounding context.

sh
�: 1.0.0
# 贡献者: Molty (OpenClaw Agent)

set -e

echo "🔧 Agent Reach 安装脚本"
echo "========================================"
echo "环境检测..."
echo "Python版本: $(python3 --version)"
echo "系统: $(uname -a)"
echo ""

# 检查权限
if [ ! -w "$HOME" ]; then
    echo "❌ 错误: 无法写入用户主目录"
    exit 1
fi

# 安装Agent Reach
echo "📦 安装Agent Reach..."
pip install https://github.com/Panniantong/agent-reach/archive/main.zip --break-system-packages

# 自动配置
echo "⚙️ 自动配置..."
agent-reach install --env=auto

# 额外配置
echo "🔧 额外配置..."
mcporter config add exa https://mcp.exa.ai/mcp 2>/dev/null || true

# 验证安装
echo "✅ 验证安装..."
agent-reach doctor

echo ""
echo "🎉 安装完成!"
echo "运行 'agent-reach doctor' 检查状态"
echo "运行 'agent-reach watch' 监控更新"

YARA rule 'agent_skill_remote_bootstrap_execution': Remote script or code download followed by execution/bootstrap installation [agent_skills]

High
Category
YARA Match
Confidence
97% confidence
Finding

This command downloads and installs code directly from a remote GitHub archive, creating a supply-chain risk because users are executing unreviewed, mutable remote content. The danger is amplified by the simultaneous use of --break-system-packages, which can make any compromise affect the system Python environment rather than an isolated environment.

Content

Scanner excerpt · troubleshooting.md (reported line 15)May include surrounding context.

Agent Reach 故障排除指南

常见问题

1. 权限问题

症状: externally-managed-environment 错误

bash
error: externally-managed-environment

解决方案:

bash
# 使用 --break-system-packages 参数
pip install https://github.com/Panniantong/agent-reach/archive/main.zip --break-system-packages

原因: Python 3.13+ 默认启用外部包管理保护

2. GitHub CLI 安装失败

症状: 权限不足或安装失败

bash
[!] gh CLI install failed

解决方案:

3. Exa 搜索未配置

症状: mcporter已装但Exa未配置

bash
[X] 全网语义搜索 — mcporter 已装但 Exa 未配置

解决方案:

bash
mcporter config add exa https://mcp.exa.ai/mcp

4. �

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README instructs users to run a direct pip installation from a GitHub ZIP and explicitly use --break-system-packages, which can override distro-managed Python protections and destabilize the host environment. Even if intended as a convenience workaround, encouraging this without clear isolation guidance, risk warnings, or safer alternatives increases the chance of system package corruption and unintended code execution from a mutable remote source.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs users to install a package directly from a remote GitHub archive while also using --break-system-packages, but it does not warn that this bypasses Python's package-management protections and can modify the system interpreter environment. In an agent-skill context, this increases risk because users or agents may run the command verbatim, potentially destabilizing the host or installing unreviewed code from a mutable branch archive.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The proxy example embeds credentials directly in the command line (http://user:pass@ip:port) without any warning about secret exposure. In practice, such examples normalize unsafe handling of credentials, which can leak via shell history, process listings, logs, screenshots, or copied documentation.

Content

No source excerpt is available for this finding.

File System Enumeration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.

Content

Scanner excerpt · SKILL.md (reported line 108)May include surrounding context.

agent-reach doctor | grep "✅"

验证技能安装路径

ls -la /home/pan/.openclaw/skills/agent-reach/ ls -la /home/pan/.claude/skills/agent-reach/

text

File System Enumeration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

agent-reach doctor | grep "✅"

验证技能安装路径

ls -la /home/pan/.openclaw/skills/agent-reach/ ls -la /home/pan/.claude/skills/agent-reach/

text

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

验证技能安装路径

ls -la /home/pan/.openclaw/skills/agent-reach/ ls -la /home/pan/.claude/skills/agent-reach/

text

## 贡献信息

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script installs software from a remote URL, modifies Python package state with --break-system-packages, runs automatic environment configuration, and adds external service config without any confirmation. In an agent-skill context, unattended execution makes silent environment changes more dangerous because the user may not realize their system and tool configuration are being altered.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The installer silently adds configuration for an external MCP service (exa) that is not strictly required to install the advertised package. This expands the user's environment and trust boundary without informed consent, creating unnecessary exposure to external services and making the script behave beyond core installation scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The troubleshooting guide instructs users to run pip install directly from a GitHub archive URL while also using --break-system-packages, which disables Python's environment safety protections and can modify system-managed packages. In a user-facing skill, this is dangerous because it encourages risky installation behavior without warning about package integrity, environment isolation, or system breakage.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
79% confidence
Finding

The documentation recommends sudo snap install gh, which requires elevated privileges and changes the host system. Although this is a common administrative action, including privileged commands in a troubleshooting skill without a cautionary note increases the risk of unnecessary or unsafe root-level execution.

Content

Scanner excerpt · troubleshooting.md (reported line 29)May include surrounding context.

md
**解决方案**:
- 手动安装: https://cli.github.com
- 或使用Snap: `sudo snap install gh`

### 3. Exa 搜索未配置

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The proxy example embeds credentials directly in the command line (http://user:pass@ip:port), which can expose secrets through shell history, process listings, logs, or screenshots. While presented as a placeholder, the lack of a privacy warning makes it more likely users will paste real credentials unsafely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The examples instruct users to place proxy credentials and Twitter cookies directly on the command line without any warning about secret exposure. Command-line arguments can be captured in shell history, process listings, logs, or screenshots, which can leak reusable credentials or session tokens to other users or systems.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file presents all user-facing instructions in Chinese and does not offer an alternative language or indicate that the skill is intended only for a Chinese-speaking or region-specific audience. This can violate a language/locale policy that requires user choice or explicit justification for a fixed language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script's comments and echoed status messages are written in Chinese, which imposes a specific language on users. There is no opt-in, language selection, or documented reason that the skill is intended only for a Chinese-speaking audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The natural-language description is entirely in Chinese ("Agent Reach 完整安装与配置解决方案") with no indication that the skill is region-specific or that users can opt into another language. Under the locale policy, forcing a specific language without user choice or documented justification is a policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

A language or locale policy issue exists when a skill forces a specific language without user opt-in. This file's headings, descriptions, and examples are all presented in Chinese, and there is no indication that users may choose another language or that the locale is intentionally constrained.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The examples invoke external services such as Exa and Jina Reader for search and webpage retrieval, which transmit user-supplied queries or URLs to remote providers. The markdown does not disclose this privacy-relevant behavior or advise users to avoid sending sensitive data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.