link-to-im
Audited by Socket on Sep 18, 2026
5 alerts found:
Anomalyx4SecurityThe fragment is an integration layer for an AI coding agent with intentional command, file, and MCP execution capabilities. It passes credentials and the process environment to the configured Codex SDK and allows environment-controlled sandbox and approval overrides, so deployments should restrict those variables and use least-privilege policies. The dynamic import is unusual but narrowly scoped and plausibly legitimate. No clear evidence of malware, data theft, obfuscation, hardcoded credentials, or unauthorized exfiltration appears in the supplied portion.
The fragment implements expected daemon lifecycle management and contains no clear malicious behavior or data exfiltration. The main security concerns are execution of the shell-based config.env file, automatic execution of npm build scripts, and possible Windows command injection caused by unescaped arguments in a PowerShell -Command string. These should be mitigated by parsing configuration as data where possible, validating/escaping arguments, avoiding ExecutionPolicy Bypass when unnecessary, and constraining build inputs.
No direct malicious behavior such as credential theft, data exfiltration, reverse-shell creation, or system damage is present in this installer fragment. It is a conventional project installer, but it carries significant supply-chain risk because it downloads mutable remote code and executes npm installation and build scripts with user privileges. The unpinned repository, dependency installation, and silent error handling warrant review and would be safer with commit or tag pinning, integrity verification, and explicit inspection of package scripts and dependencies.
The fragment is an update configuration with a notable supply-chain risk: it trusts mutable Git content and executes npm installation and build commands after git pull. This could permit malicious behavior if the repository, package scripts, or dependencies are compromised, but the provided configuration contains no direct malware, credential theft, exfiltration, or backdoor logic. Manual update policy reduces exposure if enforced by the surrounding system. Pinning updates to verified commits or signed releases and reviewing npm lifecycle scripts would reduce risk.
This package executes local postinstall scripts that can perform arbitrary actions and depends on non-registry sources (file: local package and github: optional deps). That combination raises a significant untrusted-code-execution risk: the scripts could modify source, introduce telemetry/data-exfiltration, or perform other malicious actions during install. Before installing in any sensitive or privileged environment you should inspect the contents of scripts/apply-bridge-patches.mjs, scripts/patch-sdk-streaming.mjs and the code under ./packages/agent-to-im-core, and review any GitHub-sourced optional deps. Prefer to install in a sandbox or CI runner, pin/replace non-registry deps with vetted registry versions, or remove/disable postinstall scripts if you cannot audit them.