link-to-im
Fail
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONPERSISTENCE
Full Analysis
- [REMOTE_CODE_EXECUTION]: The repository provides and documents an installation method using
curl | bashtargeting a script on GitHub. While the script is a vendor resource belonging to the author, this pattern is inherently high-risk as it executes remote code without local verification. - [DYNAMIC_EXECUTION]: The skill performs several high-risk dynamic operations:
scripts/patch-sdk-streaming.mjsprogrammatically modifies the source code of the@anthropic-ai/claude-agent-sdkdependency withinnode_modulesduring the build process to alter its internal behavior.src/update-adapter.tsandsrc/codex-provider.tsuseFunctionconstructors to execute dynamicimport()calls for optional dependencies.scripts/spawn-fix.cjsmonkey-patcheschild_processmethods at runtime to facilitate environment-specific command execution on Windows.- [COMMAND_EXECUTION]: The
SKILL.mdpreamble instructs the agent to silently runupdate-kitfor version checks every session. Additionally, the skill's self-healing protocol (UDD) involves the agent running analysis and repair commands in a subagent context. - [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to process and forward untrusted data from IM platforms to the AI agent.
- Ingestion points: Inbound messages from Telegram, Discord, Feishu, QQ, and WeChat are routed into the agent's context.
- Boundary markers: The system uses sender tags and specific formatting to delineate user content, but the agent remains susceptible to adversarial input within the IM messages.
- Capability inventory: The agent is authorized to use
Bash,Read,Write, andEdittools, creating a significant impact potential for successful injection. - Sanitization: The skill implements input validation for null bytes, path traversal, and specific dangerous command patterns in
src/lib/bridge/security/validators.ts. - [PERSISTENCE]: The skill manages the lifecycle of local background daemons and integrates with system supervisors (such as
launchdon macOS and Windows Services via WinSW/NSSM) to ensure the bridge service persists across reboots and user sessions.
Recommendations
- HIGH: Downloads and executes remote code from: https://raw.githubusercontent.com/d-wwei/Agents-To-IM/main/scripts/install.sh - DO NOT USE without thorough review
Audit Metadata