Agent-Reach Gains 1,696 Stars in a Day, and Its Own Guide Warns of Weekly Scraper Breakage
Software / news
Agent-Reach Gains 1,696 Stars in a Day, and Its Own Guide Warns of Weekly Scraper Breakage
The MIT-licensed tool gives coding agents access to X, Reddit and YouTube through cookies and community scrapers, and its issue tracker holds an open security-policy mismatch.
Agent-Reach, a Python command-line tool that lets AI coding agents read Twitter/X, Reddit, YouTube, GitHub and a dozen other sites, gained 1,696 GitHub stars on Oct. 4, the most of any repository on that day's trending list. Its repository showed 89.9k stars, 7.9k forks and 95 open issues when The Terminal read it. It is MIT licensed and maintained by a developer who goes by Panniantong.
The pitch is in the repository's title: "Give your AI agent eyes to see the entire internet." The README says the tool handles installing, configuring and routing the third-party scrapers an agent needs, so Claude Code, Cursor or OpenClaw can fetch a YouTube transcript or a Reddit thread through one interface.
What it covers and where it stops
The README lists web pages, YouTube, RSS, GitHub, Twitter/X, Reddit, Bilibili, Xiaohongshu, Facebook, Instagram, LinkedIn, Boss Zhipin, V2EX and Xueqiu. Several of those have no official free API, so the tool leans on browser sessions and community scrapers.
That produces a short list of caveats, all from the project's own documentation:
| Platform | What the README says |
|---|---|
| No zero-configuration path; anonymous APIs are blocked | |
| Facebook, Instagram, Reddit | Need login credentials or a browser session |
| Bilibili via yt-dlp | Deprecated after anti-scraping measures |
The install step is the unusual part. The README tells the user to ask their own agent to install the tool from a document on raw.githubusercontent.com, after which the agent configures itself. The Terminal did not read that install document, and nothing here says what it contains.
Cookies and the ban risk
Login cookies are stored in ~/.agent-reach/config.yaml with file mode 600, readable only by the owner. The README says they are not uploaded. It also advises using a separate throwaway account for any platform that needs a login, because non-standard access patterns can get an account banned.
A third-party guide from explainx.ai, dated Aug. 3, says the same in plainer terms: "Prefer alt accounts; ban risk is real." It adds: "Social platforms change anti-bot rules weekly — expect backend churn." It also separates two ideas the README blurs. In its words, "A healthy backend establishes an access path, not the accuracy or completeness of the extracted content."
For a reader who wants an agent to summarise a thread, that last sentence is the working rule. A green status check from the tool's doctor command says a channel connects. It does not say the text came back whole.
What the issue tracker shows
The 95 open issues are mostly small. One, number 702, reports that YouTube cookies are written to the config but never used by the download step, while the tool prints a success message. Another, number 685, reports the doctor command saying the web channel is fine while its Jina Reader backend is unreachable.
Issue 703 is the one about security. It says private vulnerability reporting is not enabled on the repository, which contradicts the project's SECURITY.md. That file promises acknowledgement within 48 hours and tells researchers to use GitHub's private advisory feature. The issue says the feature is switched off.
Why it is spreading, and what stars cannot say
The timing fits the current run of agent add-ons on the trending list, where skills and harness packages for coding agents hold most of the top slots. Agent-Reach solves a specific annoyance: agents cannot read the sites developers actually cite.
Stars are not adoption. They say nothing about how many people keep the tool installed after the first week, and they say nothing about how many of its scraper backends still work. A tool whose own guide predicts weekly breakage will have a different star count than active-user count.
The question for anyone installing is where the cookies end up. They sit in a YAML file that any process running as the same user can read, and committed secrets are a known failure, as Truffle Security's count of 543,699 working credentials showed. For the agent side, see Pi 1.0. The next signal is whether issue 703 gets fixed.
Sources
More in Software
- 01OpenCut Has 92,200 Stars, but the Editor People Use Is the Classic One and the Rewrite Is Not Taking ContributionsThe open-source CapCut alternative rebuilt its default branch in May. The README and a third-party walkthrough disagree on how much of the new code is Rust.
- 02Impeccable's Design Detector Runs Without a Model, but Its Open Issues Show Gaps Outside .htmlPaul Bakaus's design skill for coding agents ships 61 deterministic rules you can run from the command line. The bug tracker says where they are least reliable.
- 03A Hacker News Post Says Agents Need Documentation, Not Memory, and Its Author Wrote the Plugin That Does ThatKevin Liao's October 3 essay attacks snippet-recall memory plugins and promotes Operator Memory. A separate September essay argues the real gap is neither memory nor documents.
- 04Agent Reach, at 90,900 Stars, Reads X and Reddit for Your Agent Through Your Own CookiesThe MIT-licensed CLI routes agents to 20-plus sites with a backup backend per channel. Its README admits the login channels can get an account banned.