agent-reach

Fail

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: HIGHPRIVILEGE_ESCALATIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [PRIVILEGE_ESCALATION]: The skill instructs the user to use sudo cp to move the areach helper script to /usr/local/bin/areach, which grants the agent or user high-privilege access to the system path.
  • [EXTERNAL_DOWNLOADS]: The skill fetches and installs multiple third-party tools and dependencies from unverified external sources, including pipx install 'git+https://github.com/public-clis/rdt-cli.git' and update instructions hosted at raw.githubusercontent.com/Panniantong/agent-reach/main/docs/update.md.
  • [COMMAND_EXECUTION]: The core functionality of the skill relies on executing a wide range of shell commands (e.g., curl, gh, yt-dlp, twitter, rdt) through the areach host helper, which executes these commands inside a Docker container. This presents a broad attack surface for command injection if user inputs are not properly sanitized.
  • [CREDENTIALS_UNSAFE]: The skill provides instructions for handling sensitive credentials, including manually setting environment variables like TWITTER_AUTH_TOKEN and TWITTER_CT0, and using a configuration command (agent-reach configure) to store API keys for Groq and OpenAI.
  • [INDIRECT_PROMPT_INJECTION]: The skill frequently ingests untrusted data from external sources such as Twitter feeds, Reddit posts, YouTube subtitles, and arbitrary web pages via Jina Reader.
  • Ingestion points: Data enters the context via curl (Jina Reader), twitter-cli, rdt-cli, and yt-dlp (subtitles).
  • Boundary markers: There are no explicit delimiters or instructions for the agent to ignore embedded commands within the fetched content.
  • Capability inventory: The skill possesses extensive capabilities including network operations (curl), file management, and tool execution (mcporter).
  • Sanitization: No evidence of sanitization or filtering of external content was found.
  • [DYNAMIC_EXECUTION]: The skill involves dynamic execution patterns such as running shell scripts (transcribe.sh) and downloading headless browsers (150MB) at runtime for specific web scrapers.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 13, 2026, 03:56 PM
Security Audit — agent-trust-hub — agent-reach