BoundBench

Agent Reach

Installer, health checker and skill that let AI coding agents read and search web pages, social platforms, video and GitHub through upstream CLIs.

github.com/Panniantong/Agent-Reach · 2026-10-05 · a19a171

Defense-in-depth score

1.9 / 10

Minimal

Agent Reach connects a coding agent to the open internet by installing third-party CLIs and telling the agent which commands to run, and its own code is careful with stored secrets and its own inputs. But it adds no safeguards around what the agent then does: untrusted web content, the user's GitHub login and arbitrary URL fetches end up in one session, with no approval step, isolation or audit trail from Agent Reach. Most installed tools are unpinned, and the search tool also reads server definitions from the workspace. Treat it as giving the agent the internet with only the host agent's own prompts as protection.

Key gaps (5)

  1. The installer's only consent step is a --system flag the agent passes itself, and the skill's references list GitHub write commands with no gate. C2 · Approval gates
  2. Every command the skill directs and every package the installer adds runs on the host as the user, with the full environment and network. C4 · Code-execution isolation
  3. Untrusted web content, the user's GitHub login and arbitrary URL fetch share one session, so an injected page can leak data and act on the user's account. C5 · Untrusted input blast radius
  4. The search command the skill runs also reads MCP server definitions from the workspace, so a cloned repository can change which server starts, with no trust prompt. C6 · Memory, context & configuration integrity
  5. Installed third-party tools (mostly unpinned global npm and PyPI packages) run as the user with the full environment and the user's logins. C7 · Third-party extensions

Criteria

C1 Identity & least privilege

Minimal 0.25 / 1.00

Agent Reach has no identity of its own: the host agent runs the upstream tools with the user's existing logins, so the zero-config GitHub channel uses whatever gh login the user has, with full read and write. Credential imports for other platforms are explicit and narrow (only the named cookies for one chosen platform, and install never reads a browser), which is a real narrowing. But every tool Agent Reach launches inherits the full environment, and nothing checks what a request is allowed to do.

C2 Approval gates

Minimal 0.17 / 1.00

Agent Reach ships no approval step of its own. Its installer is check-only unless the --system flag is passed, and it has a dry run, but that flag is passed by the agent itself once it decides the user agreed, so the gate is the model's judgement. The skill says it is for reading only, yet its GitHub reference lists commands that create issues, pull requests, repositories and releases with no risk marking. Anything consequential relies entirely on the host agent's own permission prompts.

C3 Tool & action scoping

Minimal 0.33 / 1.00

Agent Reach's own commands validate their inputs reasonably: transcription and its web reader reject non-public literal addresses, config keys are a fixed list, and responses and downloads are size-capped. But the skill routes the real work through general tools, raw curl on any URL, the full gh CLI and API, yt-dlp and shell one-liners, which Agent Reach does not check at all. The URL checks cover literal addresses only and do not follow redirects or DNS. Optional channels are opt-in one by one, but the default set already includes GitHub write and arbitrary fetch.

C4 Code-execution isolation

Minimal 0.00 / 1.00

Agent Reach provides no isolation. The skill has the host agent run shell commands, including Python one-liners and podcast scripts, directly on the user's machine, and the installer runs global npm and pipx installs, whose install scripts execute as the user. Nothing runs in a container or sandbox, so anything that goes wrong has the user's files, network and logins.

C5 Untrusted input blast radius

Minimal 0.00 / 1.00

Agent Reach exists to pour untrusted internet content (web pages, tweets, Reddit, YouTube comments, search results) into an agent that also holds the user's GitHub login and can fetch any URL. Neither the skill nor the install guide marks fetched content as untrusted, records where it came from, or limits what the agent may do after reading it. A prompt injection in any page can therefore steer the agent to leak data through a URL and act on the user's GitHub account without Agent Reach involving a human.

C6 Memory, context & configuration integrity

Minimal 0.10 / 1.00

Agent Reach keeps no memory, but two things persist into later sessions without review. Its settings file, including the network proxy that the guides tell agents to export before running tools, can be rewritten by the agent with a plain command. And the search command the skill runs reads MCP server definitions from the current working directory as well as the user's home, so a file in the workspace can change which server starts, with no trust decision. The skill itself is installed only into user-level skill folders, which is good.

C7 Third-party extensions

Minimal 0.20 / 1.00

Agent Reach is an installer for third-party tools, and most of what it installs is unpinned: mcporter, undici and OpenCLI come from global npm installs at whatever version is latest, twitter-cli and bilibili-cli from PyPI likewise, and the setup and update guides the agent follows are read from the main branch. Two Python CLIs are pinned to exact commits, which helps, but nothing is checked against a hash or signature. Installs need the --system flag, which the agent passes itself. Everything installed runs as the user with full access.

C8 Secrets & sensitive-data protection

Moderate 0.50 / 1.00

Agent Reach handles the secrets it stores carefully: the settings file is written atomically with owner-only permissions and refuses symlinks, secret settings are masked when shown, error and doctor output is scrubbed of credentials in URLs, values can be entered through a hidden prompt, and there is no telemetry. The weak spot is the setup flow: the install guide asks users to paste cookies and API keys to the agent, and the Twitter instructions have the agent put tokens in shell commands, so those secrets pass through the model provider. Tokens are long-lived and stored in plain text.

C9 Audit & traceability

Minimal 0.00 / 1.00

Agent Reach keeps no record of what the agent did with it. There is no audit log of installs, configuration changes or the upstream commands the skill directs, and its own logging is switched off unless --verbose is passed, and then only goes to the terminal. Reconstructing an incident depends entirely on the host agent's transcript.

C10 Limits & kill switch

Minimal 0.38 / 1.00

Agent Reach's own commands are well bounded: every subprocess it starts has a timeout, transcription caps file size, audio length and number of chunks, and its web reader caps response size. But those bounds cover only Agent Reach's own commands; the curl, yt-dlp, gh and social-media commands the skill sends the agent to run have no limits from Agent Reach, and the skill encourages fetching from several platforms in parallel. The install guide also suggests a daily scheduled check that keeps running after a session ends.