T03 · Remote Payload Retrieval and Execution
- Location
install.sh:21- Finding
Mutable Remote Python Package Is Downloaded and Executed Without Integrity Verification
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is an installer for Agent Reach, but it can automatically run an unpinned remote installer and change the user's Python and agent configuration without enough safeguards.
Review this carefully before installing. Avoid running npm install scripts for it and do not use the provided --break-system-packages command on your main Python environment. Prefer an isolated environment, a pinned and verified Agent Reach release, and manual opt-in for Exa or other MCP services. Do not paste real proxy passwords or Twitter cookies directly into command-line examples.
install.sh:21Mutable Remote Python Package Is Downloaded and Executed Without Integrity Verification
install.sh:23Installer Bypasses Python System-Package Protection
package.json:20NPM Install Lifecycle Automatically Launches the Remote-Payload Installer
usage-examples.md:15Proxy Credentials and Twitter Session Cookies Are Passed Through Command-Line Arguments
usage-examples.md:246Predictable Shared Temporary Cache Lacks Permission and Symlink Protections
The README promotes installing and executing code directly from a remote GitHub archive on the main branch, followed by additional bootstrap commands. This is dangerous because the referenced content is mutable, unauthenticated in the command itself, and paired with environment-modifying installation steps, creating a supply-chain and remote code execution risk if the upstream repository is compromised or changed maliciously.
─ troubleshooting.md # 故障排除 └── usage-examples.md # 使用示例
## 🔧 系统要求
- **Python**: 3.13+
- **Node.js**: 22+
- **操作系统**: Linux, macOS, Windows (WSL)
- **权限**: 用户主目录写入权限
## 📦 安装方式
### 方式1: 使用安装脚本
```bash
chmod +x install.sh
./install.sh
# 1. 安装Agent Reach
pip install https://github.com/Panniantong/agent-reach/archive/main.zip --break-system-packages
# 2. 自动配置
agent-reach install --env=auto
# 3. 配置Exa搜索
mcporter config add exa https://mcp.exa.ai/mcp
# 4. 验证安装
agent-reach doctor
The skill instructs installation directly from https://github.com/.../archive/main.zip, which fetches code from a mutable remote source and immediately installs it. In a skill document, this is especially risky because users may execute it without review; if the repository or branch contents change or are compromised, arbitrary code can be installed, and the added --break-system-packages increases host-level impact.
基于实际部署经验,包含问题诊断和解决方案。适用于OpenClaw、Claude Code等AI Agent环境。
# 解决权限问题
pip install https://github.com/Panniantong/agent-reach/archive/main.zip --break-system-packages
agent-reach install --env=auto
agent-reach doctor
# 配置Exa搜索
mcporter config add exa https://mcp.exa.ai/mcp
症状: externally-managed-environment 错误
解决方案: 使用 --break-system-packages 参数
原因: Python 3.13+ 默认启用外部包管理保护
Referenced artifact was not completely inspected
- `SKILL.md` - 本技能文档
The script installs directly from a GitHub ZIP on the main branch, which is mutable and not pinned or integrity-checked. This is dangerous because whoever controls that repository or any compromised dependency path can change the installed code at any time, and the script immediately bootstraps it into the user's environment.
�: 1.0.0
# 贡献者: Molty (OpenClaw Agent)
set -e
echo "🔧 Agent Reach 安装脚本"
echo "========================================"
echo "环境检测..."
echo "Python版本: $(python3 --version)"
echo "系统: $(uname -a)"
echo ""
# 检查权限
if [ ! -w "$HOME" ]; then
echo "❌ 错误: 无法写入用户主目录"
exit 1
fi
# 安装Agent Reach
echo "📦 安装Agent Reach..."
pip install https://github.com/Panniantong/agent-reach/archive/main.zip --break-system-packages
# 自动配置
echo "⚙️ 自动配置..."
agent-reach install --env=auto
# 额外配置
echo "🔧 额外配置..."
mcporter config add exa https://mcp.exa.ai/mcp 2>/dev/null || true
# 验证安装
echo "✅ 验证安装..."
agent-reach doctor
echo ""
echo "🎉 安装完成!"
echo "运行 'agent-reach doctor' 检查状态"
echo "运行 'agent-reach watch' 监控更新"
This command downloads and installs code directly from a remote GitHub archive, creating a supply-chain risk because users are executing unreviewed, mutable remote content. The danger is amplified by the simultaneous use of --break-system-packages, which can make any compromise affect the system Python environment rather than an isolated environment.
症状: externally-managed-environment 错误
error: externally-managed-environment
解决方案:
# 使用 --break-system-packages 参数
pip install https://github.com/Panniantong/agent-reach/archive/main.zip --break-system-packages
原因: Python 3.13+ 默认启用外部包管理保护
症状: 权限不足或安装失败
[!] gh CLI install failed
解决方案:
sudo snap install gh症状: mcporter已装但Exa未配置
[X] 全网语义搜索 — mcporter 已装但 Exa 未配置
解决方案:
mcporter config add exa https://mcp.exa.ai/mcp
The README instructs users to run a direct pip installation from a GitHub ZIP and explicitly use --break-system-packages, which can override distro-managed Python protections and destabilize the host environment. Even if intended as a convenience workaround, encouraging this without clear isolation guidance, risk warnings, or safer alternatives increases the chance of system package corruption and unintended code execution from a mutable remote source.
The skill instructs users to install a package directly from a remote GitHub archive while also using --break-system-packages, but it does not warn that this bypasses Python's package-management protections and can modify the system interpreter environment. In an agent-skill context, this increases risk because users or agents may run the command verbatim, potentially destabilizing the host or installing unreviewed code from a mutable branch archive.
The proxy example embeds credentials directly in the command line (http://user:pass@ip:port) without any warning about secret exposure. In practice, such examples normalize unsafe handling of credentials, which can leak via shell history, process listings, logs, screenshots, or copied documentation.
Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.
agent-reach doctor | grep "✅"
ls -la /home/pan/.openclaw/skills/agent-reach/ ls -la /home/pan/.claude/skills/agent-reach/
Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.
agent-reach doctor | grep "✅"
ls -la /home/pan/.openclaw/skills/agent-reach/ ls -la /home/pan/.claude/skills/agent-reach/
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
ls -la /home/pan/.openclaw/skills/agent-reach/ ls -la /home/pan/.claude/skills/agent-reach/
## 贡献信息
The script installs software from a remote URL, modifies Python package state with --break-system-packages, runs automatic environment configuration, and adds external service config without any confirmation. In an agent-skill context, unattended execution makes silent environment changes more dangerous because the user may not realize their system and tool configuration are being altered.
The installer silently adds configuration for an external MCP service (exa) that is not strictly required to install the advertised package. This expands the user's environment and trust boundary without informed consent, creating unnecessary exposure to external services and making the script behave beyond core installation scope.
The troubleshooting guide instructs users to run pip install directly from a GitHub archive URL while also using --break-system-packages, which disables Python's environment safety protections and can modify system-managed packages. In a user-facing skill, this is dangerous because it encourages risky installation behavior without warning about package integrity, environment isolation, or system breakage.
The documentation recommends sudo snap install gh, which requires elevated privileges and changes the host system. Although this is a common administrative action, including privileged commands in a troubleshooting skill without a cautionary note increases the risk of unnecessary or unsafe root-level execution.
**解决方案**:
- 手动安装: https://cli.github.com
- 或使用Snap: `sudo snap install gh`
### 3. Exa 搜索未配置
The proxy example embeds credentials directly in the command line (http://user:pass@ip:port), which can expose secrets through shell history, process listings, logs, or screenshots. While presented as a placeholder, the lack of a privacy warning makes it more likely users will paste real credentials unsafely.
The examples instruct users to place proxy credentials and Twitter cookies directly on the command line without any warning about secret exposure. Command-line arguments can be captured in shell history, process listings, logs, or screenshots, which can leak reusable credentials or session tokens to other users or systems.
The file presents all user-facing instructions in Chinese and does not offer an alternative language or indicate that the skill is intended only for a Chinese-speaking or region-specific audience. This can violate a language/locale policy that requires user choice or explicit justification for a fixed language.
The script's comments and echoed status messages are written in Chinese, which imposes a specific language on users. There is no opt-in, language selection, or documented reason that the skill is intended only for a Chinese-speaking audience.
The natural-language description is entirely in Chinese ("Agent Reach 完整安装与配置解决方案") with no indication that the skill is region-specific or that users can opt into another language. Under the locale policy, forcing a specific language without user choice or documented justification is a policy concern.
A language or locale policy issue exists when a skill forces a specific language without user opt-in. This file's headings, descriptions, and examples are all presented in Chinese, and there is no indication that users may choose another language or that the locale is intentionally constrained.
The examples invoke external services such as Exa and Jina Reader for search and webpage retrieval, which transmit user-supplied queries or URLs to remote providers. The markdown does not disclose this privacy-relevant behavior or advise users to avoid sending sensitive data.
No suspicious patterns detected.