agent-reach

Warn

Audited by Socket on Sep 20, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s broad internet-research purpose generally matches its capabilities, but its footprint is larger than a simple search skill: it auto-installs/updates executable tooling, encourages browser cookie extraction, and relies on multiple third-party CLIs/MCP servers. Data flows are mostly consistent with the stated purpose, yet the mutable GitHub-archive installer and credential-bearing integrations make this a high supply-chain and credential-handling risk rather than confirmed malware.

Confidence: 88%Severity: 74%
AnomalyLOW
references/setup-channels.md

The supplied fragment is configuration documentation and does not itself contain executable malicious behavior. It presents significant operational security risks because it requests proxy credentials, API keys, and broad browser-cookie extraction, and it relies on unverified third-party Docker, PyPI, and Git packages. Review the referenced tools before use, restrict MCP services to localhost with authentication where possible, and avoid exporting all browser cookies unless necessary.

Confidence: 97%Severity: 62%
Audit Metadata
Analyzed At
Sep 20, 2026, 12:58 AM
Package URL
pkg:socket/skills-sh/terrylica%2Fcc-skills%2Fagent-reach%2F@3a3d76e187c2c6f7b1ab9ac3f3cd2f4b0d960b508f6c1e0f998b56e01317940c
Security Audit — socket — agent-reach