Back to skill

Security audit

Agent Reach.Bak

Security checks for vulnerabilities and agentic risk

Overview

This skill is broadly aligned with web and social-platform access, but it asks agents to use sensitive browser/session credentials and mutable remote setup instructions with insufficient local guardrails.

Review this skill before installing if you will enable authenticated channels. Prefer read-only use first, use secondary accounts for cookie-based platforms, approve each posting or publishing action explicitly, and do not let an agent follow remote setup commands, install global packages, use browser cookies, or configure proxies until you have seen and approved the exact commands.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:163
Finding

Mutable Remote Setup Guide Creates an Unreviewed Supply-Chain Trust Boundary

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 163-166
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

text
If a channel needs setup (cookies, Docker, etc.), fetch the install guide:
https://raw.githubusercontent.com/Panniantong/agent-reach/main/docs/install.md

User only provides cookies. Everything else is your job.

Technical Analysis

The Skill delegates channel setup to a remotely hosted document on the mutable main branch. The retrieved document is not pinned to a reviewed commit, version, or integrity digest. Consequently, its effective instructions can change after this Skill package has been audited.

The broad instruction that everything other than supplying cookies is the agent's responsibility increases the likelihood that future remote instructions will be followed without a separate security review. The referenced setup scope expressly includes cookies and Docker, which may involve sensitive authentication material, dependency installation, container execution, filesystem access, or elevated operations.

This is a supply-chain weakness rather than evidence that the current remote guide is malicious. The risk arises if the upstream repository, maintainer account, hosting path, or mutable guide is compromised or changed unsafely.

Attack Path

  1. An attacker compromises the upstream repository or an authorized maintainer account, or otherwise causes malicious instructions to be added to docs/install.md on the main branch.
  2. A user requests configuration of a channel that requires setup.
  3. Following SKILL.md, the agent retrieves the current remote installation guide.
  4. The modified guide instructs the agent to install an unsafe dependency, execute a command, launch a malicious container, or mishandle supplied cookies.
  5. If the agent follows those instructions without validation or user approval, attacker-controlled actions execute with the permis ...[truncated 825 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin the installation guide to a reviewed immutable commit rather than the mutable main branch.
  • Record and verify a cryptographic digest for downloaded setup material.
  • Prefer vendoring the reviewed setup instructions into the Skill package so they are covered by the same audit.
  • Treat remotely retrieved documentation as untrusted data, not automatically executable instructions.
  • Require explicit user confirmation before installing dependencies, starting containers, changing proxy settings, handling cookies, or running privileged commands.
  • Display the exact proposed commands and their security implications before execution.
  • Run setup operations with least privilege in an isolated environment, with narrowly scoped filesystem and network access.
  • Never transmit authentication cookies to destinations that have not been explicitly disclosed and approved.

T08 · Insecure Dependencies

Note
Location
SKILL.md:159
Finding

Unpinned Global npm Package Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 159
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Low

text
- **Twitter fetch failed?** Ensure `undici` is installed: `npm install -g undici`. Configure proxy: `agent-reach configure proxy URL`.

Technical Analysis

The troubleshooting instruction installs the latest available undici release globally without a fixed version or integrity verification. This makes installation behavior dependent on mutable package-registry state. A compromised package release, maintainer account, registry response, or future unsafe release could introduce attacker-controlled installation behavior.

Global installation increases the affected scope compared with a project-local dependency. Depending on npm configuration and operating-system permissions, package installation can also invoke lifecycle scripts and modify globally available package files or executable links.

This finding does not establish that undici is malicious. It identifies the lack of version pinning, integrity controls, isolation, and explicit approval around a global dependency installation.

Attack Path

  1. An attacker compromises a relevant package release or its publication channel, or a future release introduces unsafe installation behavior.
  2. Twitter functionality fails and the troubleshooting instruction is invoked.
  3. The agent runs npm install -g undici without a pinned version or verified integrity value.
  4. npm retrieves the currently resolved package and performs its installation behavior.
  5. Malicious package content or lifecycle behavior executes with the permissions of the npm process and modifies the global npm installation scope available to that account.

Impact Assessment

Exploitation could execute code with the privileges of the account running npm and could affect that account's globally installed Node.js packages and command links. It could also a ...[truncated 382 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin undici to a specifically reviewed version rather than resolving the latest release.
  • Use a lockfile and verify package integrity through an approved registry and recorded integrity digest.
  • Prefer a project-local, isolated dependency installation over npm install -g.
  • Require explicit user approval before installing software.
  • Avoid elevated privileges and run package installation in a sandbox or disposable environment.
  • Where compatible with the package and deployment process, disable npm lifecycle scripts during installation and separately review any required scripts.
  • Periodically review and deliberately update the pinned version after vulnerability and provenance checks.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (6)

YARA rule 'info_stealer': Information stealer patterns (credential harvesting, browser data theft) [malware]

High
Category
YARA Match
Confidence
91% confidence
Finding

The recommendation to use '--cookies-from-browser chrome' instructs the agent to extract authenticated browser cookies for access to third-party services. In an agent skill, that crosses into credential/session harvesting behavior and can expose powerful account sessions to tooling that may log, persist, or misuse them.

Content

Scanner excerpt · SKILL.md (reported line 73)May include surrounding context.

L" # download subtitles, then read the .vtt file yt-dlp --dump-json "ytsearch5:query" # search

text

## Bilibili (yt-dlp)

```bash
yt-dlp --dump-json "https://www.bilibili.com/video/BVxxx"
yt-dlp --write-sub --write-auto-sub --sub-lang "zh-Hans,zh,en" --convert-subs vtt --skip-download -o "/tmp/%(id)s" "URL"

Server IPs may get 412. Use --cookies-from-browser chrome or configure proxy.

Reddit

bash
curl -s "https://www.reddit.com/r/SUBREDDIT/hot.json?limit=10" -H "User-Agent: agent-reach/1.0"
curl -s "https://www.reddit.com/search.json?q=QUERY&limit=10" -H "User-Agent: agent-reach/1.0"

Server IPs may get 403. Search via Exa instead, or configure proxy.

GitHub (gh CLI)

bash
gh search repos "query" --sort stars --limit 10
gh repo view owner/repo
gh search code "query" --language python
gh issue list -R owner/repo --state open
gh issue view 123 -R owner/repo

小红书 / XiaoHongShu (mcporter)

bas

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill advertises posting, commenting, and interacting on external platforms but does not prominently require explicit user confirmation before modifying external accounts or content. In an agent context, this creates a real risk of unauthorized or accidental actions against third-party services using the user's authenticated sessions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list includes very broad phrases like 'search online', 'research', and common Chinese equivalents that are likely to match ordinary user requests. This can cause the skill to activate unexpectedly and route benign conversations into networked actions, increasing the chance of unintended web access or external side effects.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

The skill explicitly instructs the agent to store persistent data in ~/.agent-reach/, creating cross-session state that may retain tokens, cookies, scraped content, or other sensitive artifacts. Persistent storage increases the blast radius of compromise and makes accidental reuse or leakage of prior-session data more likely in an agent environment.

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

md
## ⚠️ Workspace Rules

**Never create files in the agent workspace.** Use `/tmp/` for temporary output and `~/.agent-reach/` for persistent data.

## Web — Any URL

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The YouTube example forces subtitle language selection to "zh-Hans,zh,en", which imposes a specific locale order in the skill instructions. The file does not indicate that this is optional, user-configurable, or justified as a region-specific tool, so it creates a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The Bilibili example also fixes subtitle language selection to "zh-Hans,zh,en" rather than describing it as a user-selected option. Without an explicit opt-in or documented regional constraint, this is a natural-language locale policy violation under the review criteria.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.