agent-reach
Pass
Audited by Gen Agent Trust Hub on Aug 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill makes extensive use of external command-line interfaces (CLIs) to interact with web services. This includes
gh(GitHub),yt-dlp(YouTube/Bilibili),xhs(XiaoHongShu),twitter(Twitter/X),rdt(Reddit), andbili(Bilibili). It also utilizes a custommcportertool for Model Context Protocol (MCP) calls. - [EXTERNAL_DOWNLOADS]: The instructions guide the installation of several third-party Python packages via
pipx, includingxiaohongshu-cli,twitter-cli,rdt-cli, andbilibili-cli. It also references an installation script located athttps://raw.githubusercontent.com/Panniantong/agent-reach/main/docs/install.md. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it fetches and processes data from uncontrolled internet sources.
- Ingestion points: Content is retrieved via
curl -s "https://r.jina.ai/URL"(Jina Reader), social media posts/comments (xhs read,twitter tweet,rdt read), and video subtitles/metadata (yt-dlp). - Boundary markers: The provided files do not include specific delimiters or instructions to the agent to disregard embedded commands in the retrieved content.
- Capability inventory: The skill environment allows shell command execution, network requests, and file writes to
/tmp/and~/.agent-reach/. - Sanitization: There is no evidence of filtering or escaping external content before it is processed by the AI agent.
- [CREDENTIALS_UNSAFE]: The skill requires the management of sensitive authentication data. It instructs the agent to configure a Groq API key (
agent-reach configure groq-key YOUR_KEY) and mentions that users must provide session cookies for platforms like LinkedIn, Twitter, and Bilibili to enable scraping functionality.
Audit Metadata