agent-reach

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill makes extensive use of external command-line interfaces (CLIs) to interact with web services. This includes gh (GitHub), yt-dlp (YouTube/Bilibili), xhs (XiaoHongShu), twitter (Twitter/X), rdt (Reddit), and bili (Bilibili). It also utilizes a custom mcporter tool for Model Context Protocol (MCP) calls.
  • [EXTERNAL_DOWNLOADS]: The instructions guide the installation of several third-party Python packages via pipx, including xiaohongshu-cli, twitter-cli, rdt-cli, and bilibili-cli. It also references an installation script located at https://raw.githubusercontent.com/Panniantong/agent-reach/main/docs/install.md.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it fetches and processes data from uncontrolled internet sources.
  • Ingestion points: Content is retrieved via curl -s "https://r.jina.ai/URL" (Jina Reader), social media posts/comments (xhs read, twitter tweet, rdt read), and video subtitles/metadata (yt-dlp).
  • Boundary markers: The provided files do not include specific delimiters or instructions to the agent to disregard embedded commands in the retrieved content.
  • Capability inventory: The skill environment allows shell command execution, network requests, and file writes to /tmp/ and ~/.agent-reach/.
  • Sanitization: There is no evidence of filtering or escaping external content before it is processed by the AI agent.
  • [CREDENTIALS_UNSAFE]: The skill requires the management of sensitive authentication data. It instructs the agent to configure a Groq API key (agent-reach configure groq-key YOUR_KEY) and mentions that users must provide session cookies for platforms like LinkedIn, Twitter, and Bilibili to enable scraping functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 03:24 AM
Security Audit — agent-trust-hub — agent-reach