agent-reach
Fail
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: HIGHPRIVILEGE_ESCALATIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [PRIVILEGE_ESCALATION]: The skill instructs the user to use
sudo cpto move theareachhelper script to/usr/local/bin/areach, which grants the agent or user high-privilege access to the system path. - [EXTERNAL_DOWNLOADS]: The skill fetches and installs multiple third-party tools and dependencies from unverified external sources, including
pipx install 'git+https://github.com/public-clis/rdt-cli.git'and update instructions hosted atraw.githubusercontent.com/Panniantong/agent-reach/main/docs/update.md. - [COMMAND_EXECUTION]: The core functionality of the skill relies on executing a wide range of shell commands (e.g.,
curl,gh,yt-dlp,twitter,rdt) through theareachhost helper, which executes these commands inside a Docker container. This presents a broad attack surface for command injection if user inputs are not properly sanitized. - [CREDENTIALS_UNSAFE]: The skill provides instructions for handling sensitive credentials, including manually setting environment variables like
TWITTER_AUTH_TOKENandTWITTER_CT0, and using a configuration command (agent-reach configure) to store API keys for Groq and OpenAI. - [INDIRECT_PROMPT_INJECTION]: The skill frequently ingests untrusted data from external sources such as Twitter feeds, Reddit posts, YouTube subtitles, and arbitrary web pages via Jina Reader.
- Ingestion points: Data enters the context via
curl(Jina Reader),twitter-cli,rdt-cli, andyt-dlp(subtitles). - Boundary markers: There are no explicit delimiters or instructions for the agent to ignore embedded commands within the fetched content.
- Capability inventory: The skill possesses extensive capabilities including network operations (
curl), file management, and tool execution (mcporter). - Sanitization: No evidence of sanitization or filtering of external content was found.
- [DYNAMIC_EXECUTION]: The skill involves dynamic execution patterns such as running shell scripts (
transcribe.sh) and downloading headless browsers (150MB) at runtime for specific web scrapers.
Recommendations
- AI detected serious security threats
Audit Metadata