Agent Reach, at 90,900 Stars, Reads X and Reddit for Your Agent Through Your Own Cookies
Software / news
Agent Reach, at 90,900 Stars, Reads X and Reddit for Your Agent Through Your Own Cookies
The MIT-licensed CLI routes agents to 20-plus sites with a backup backend per channel. Its README admits the login channels can get an account banned.
Agent Reach, an MIT-licensed command-line tool that lets AI agents read YouTube, X, Reddit, GitHub, Bilibili and more than a dozen other sites, had 90.9k stars on Oct. 5. Its README warns that the channels needing a login can get the account banned. That warning matters because three of its channels depend on it.
What the tool is
The repository, built by a developer using the handle Panniantong, listed 8.0k forks, 97 open issues and 113 pull requests. It gained 980 stars in a day, according to the GitHub trending list.
An explainx.ai guide calls it a capability layer: it installs backends, probes them with an agent-reach doctor command, and routes each channel to a healthy one. That guide put the project near 65K stars, so the count has moved by about 26,000 since it was written.
How each channel gets its data
The README says each platform has a first-choice backend and a backup, and that changing the access method means reordering a list rather than rewriting code. Its worked example is Bilibili: after yt-dlp was blocked in June 2026, the tool switched to bili-cli.
| Channel | Backend named | Login needed |
|---|---|---|
| Web pages | Jina Reader | No |
| YouTube | yt-dlp captions and search | No |
| GitHub | gh CLI | Public repos, no |
| Bilibili | bili-cli | No |
| X, Reddit, Xiaohongshu | Cookies or OpenCLI | Yes |
Sources: the project README and the explainx.ai guide.
The cookie trade
For the login channels, the cookies sit in ~/.agent-reach/config.yaml with permission 600. The README says nothing is uploaded, and the code is open to audit. It also says platforms can detect non-browser calls, and it recommends a throwaway account over a main one.
The explainx guide adds that OpenCLI reuses an existing Chrome session instead of injecting credentials, and that it does not work on headless servers. It puts a residential proxy at about $1 a month for server deployments and calls automation against these sites a terms-of-service risk.
So the person who pastes their real X cookie into a config file gets a file that grants full access to that account, held next to an agent that reads untrusted web text. That is the exposure to weigh, and the README's own advice to use an alt account is the mitigation.
The install is a sentence to your agent
The README's install route is a sentence you give your agent, asking it to install Agent Reach from a docs/install.md file on the repository's main branch. It does not modify the system without the --system flag. Still, the instructions come from a branch that changes whenever the maintainer pushes. A reader who wants to pin them would need to copy a commit-specific URL by hand.
What the tracker shows
The newest issues read as maintenance of a fast-moving wrapper, not as a security audit.
- #732 (Sept. 29): doctor --json hangs indefinitely, labelled a regression.
- #740 (Oct. 1): OpenCLI channels reported as not connected.
- #742 (Oct. 2): YouTube subtitles arrive machine-translated.
- #774 (Oct. 4): a proposed optional hosted transcript backend for YouTube.
Another open issue says private vulnerability reporting is not switched on, although SECURITY.md describes it, according to the issue list.
The repository does not claim to replace official APIs, and the explainx guide says the same for anything needing guaranteed write access. Compare the memory-capture approach in Claude-Mem, which also hands an agent local state it did not have before; both reward a read of the code before installing. See also our report on LeCun and leaky agent sandboxes.
The check that settles whether the routing holds is agent-reach doctor itself. Issue #732 should be closed before anyone scripts it.
Sources
More in Software
- 01OpenCut Has 92,200 Stars, but the Editor People Use Is the Classic One and the Rewrite Is Not Taking ContributionsThe open-source CapCut alternative rebuilt its default branch in May. The README and a third-party walkthrough disagree on how much of the new code is Rust.
- 02Impeccable's Design Detector Runs Without a Model, but Its Open Issues Show Gaps Outside .htmlPaul Bakaus's design skill for coding agents ships 61 deterministic rules you can run from the command line. The bug tracker says where they are least reliable.
- 03A Hacker News Post Says Agents Need Documentation, Not Memory, and Its Author Wrote the Plugin That Does ThatKevin Liao's October 3 essay attacks snippet-recall memory plugins and promotes Operator Memory. A separate September essay argues the real gap is neither memory nor documents.
- 04Rust Patch Set Headstart Claims 54% Faster cargo check, Has No Licence and Is Seven Days OldThe numbers come from the project's own benchmark page, run on a 16-core AMD EPYC machine. Its readiness document says the patches are not ready to merge.