skills/d-wwei/agents-to-im/link-to-im/Gen Agent Trust Hub

link-to-im

Fail

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONPERSISTENCE
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The repository provides and documents an installation method using curl | bash targeting a script on GitHub. While the script is a vendor resource belonging to the author, this pattern is inherently high-risk as it executes remote code without local verification.
  • [DYNAMIC_EXECUTION]: The skill performs several high-risk dynamic operations:
  • scripts/patch-sdk-streaming.mjs programmatically modifies the source code of the @anthropic-ai/claude-agent-sdk dependency within node_modules during the build process to alter its internal behavior.
  • src/update-adapter.ts and src/codex-provider.ts use Function constructors to execute dynamic import() calls for optional dependencies.
  • scripts/spawn-fix.cjs monkey-patches child_process methods at runtime to facilitate environment-specific command execution on Windows.
  • [COMMAND_EXECUTION]: The SKILL.md preamble instructs the agent to silently run update-kit for version checks every session. Additionally, the skill's self-healing protocol (UDD) involves the agent running analysis and repair commands in a subagent context.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to process and forward untrusted data from IM platforms to the AI agent.
  • Ingestion points: Inbound messages from Telegram, Discord, Feishu, QQ, and WeChat are routed into the agent's context.
  • Boundary markers: The system uses sender tags and specific formatting to delineate user content, but the agent remains susceptible to adversarial input within the IM messages.
  • Capability inventory: The agent is authorized to use Bash, Read, Write, and Edit tools, creating a significant impact potential for successful injection.
  • Sanitization: The skill implements input validation for null bytes, path traversal, and specific dangerous command patterns in src/lib/bridge/security/validators.ts.
  • [PERSISTENCE]: The skill manages the lifecycle of local background daemons and integrates with system supervisors (such as launchd on macOS and Windows Services via WinSW/NSSM) to ensure the bridge service persists across reboots and user sessions.
Recommendations
  • HIGH: Downloads and executes remote code from: https://raw.githubusercontent.com/d-wwei/Agents-To-IM/main/scripts/install.sh - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 18, 2026, 05:23 PM
Security Audit — agent-trust-hub — link-to-im