skills/hk-hub/agentskills/ima-skills/Gen Agent Trust Hub

ima-skills

Warn

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: MEDIUMCREDENTIALS_UNSAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes dynamic context injection (Claude Code ! syntax) in SKILL.md to execute shell commands when the skill is loaded. These commands probe the local file system for sensitive configuration files located at ~/.config/ima/client_id and ~/.config/ima/api_key. While designed for setup verification, this pattern involves automated shell execution targeting user-owned sensitive paths.
  • [CREDENTIALS_UNSAFE]: The skill manages authentication using Client IDs and API Keys that users are instructed to store in plaintext files within the ~/.config/ima/ directory. These secrets are subsequently read and processed by the skill's API wrapper scripts.
  • [REMOTE_CODE_EXECUTION]: The ima_api.cjs script implements a self-update logic that queries the remote endpoint ima.qq.com. If an update is detected, the script fetches a natural language instruction (prompt) from the server and outputs it to the agent. This allows a remote service to inject dynamic instructions into the agent's execution context.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes content from an external knowledge base and notes platform. The ingestion of this untrusted data without explicit sanitization or robust structural delimiters creates a surface for indirect prompt injection, where malicious instructions embedded in documents could influence the agent's behavior.
  • Ingestion points: API responses from get_doc_content, search_note, get_knowledge_list, and search_knowledge are directly processed in the agent context.
  • Boundary markers: The instructions provide guidelines for handling privacy but do not define technical delimiters to isolate processed content.
  • Capability inventory: The skill possesses shell execution capabilities (via scripts), file system access, and network access to ima.qq.com and *.myqcloud.com.
  • Sanitization: No explicit escaping or content validation for injection patterns is performed before data is presented to the agent.
  • [EXTERNAL_DOWNLOADS]: The skill communicates with official Tencent domains (ima.qq.com and *.myqcloud.com) for its core functionality, including API calls and file uploads to Cloud Object Storage (COS).
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 19, 2026, 05:30 PM
Security Audit — agent-trust-hub — ima-skills