Agent Reach.Bak

PassAudited by VirusTotal on Mar 23, 2026.

Findings (1)

The skill bundle provides extensive web-scraping and social media interaction capabilities but introduces significant risk by instructing the agent to fetch and execute installation steps from a remote GitHub URL (install.md) and manage sensitive session cookies for multiple platforms. It utilizes non-standard CLI tools like mcporter and xreach and directs the agent to perform system-level configurations (e.g., proxy settings, package installation) and store persistent data in ~/.agent-reach/, bypassing standard workspace boundaries. The future-dated metadata (2026) in _meta.json is an additional anomaly.