ima-skills
Warn
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: MEDIUMCREDENTIALS_UNSAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes dynamic context injection (Claude Code
!syntax) inSKILL.mdto execute shell commands when the skill is loaded. These commands probe the local file system for sensitive configuration files located at~/.config/ima/client_idand~/.config/ima/api_key. While designed for setup verification, this pattern involves automated shell execution targeting user-owned sensitive paths. - [CREDENTIALS_UNSAFE]: The skill manages authentication using Client IDs and API Keys that users are instructed to store in plaintext files within the
~/.config/ima/directory. These secrets are subsequently read and processed by the skill's API wrapper scripts. - [REMOTE_CODE_EXECUTION]: The
ima_api.cjsscript implements a self-update logic that queries the remote endpointima.qq.com. If an update is detected, the script fetches a natural language instruction (prompt) from the server and outputs it to the agent. This allows a remote service to inject dynamic instructions into the agent's execution context. - [INDIRECT_PROMPT_INJECTION]: The skill processes content from an external knowledge base and notes platform. The ingestion of this untrusted data without explicit sanitization or robust structural delimiters creates a surface for indirect prompt injection, where malicious instructions embedded in documents could influence the agent's behavior.
- Ingestion points: API responses from
get_doc_content,search_note,get_knowledge_list, andsearch_knowledgeare directly processed in the agent context. - Boundary markers: The instructions provide guidelines for handling privacy but do not define technical delimiters to isolate processed content.
- Capability inventory: The skill possesses shell execution capabilities (via scripts), file system access, and network access to
ima.qq.comand*.myqcloud.com. - Sanitization: No explicit escaping or content validation for injection patterns is performed before data is presented to the agent.
- [EXTERNAL_DOWNLOADS]: The skill communicates with official Tencent domains (
ima.qq.comand*.myqcloud.com) for its core functionality, including API calls and file uploads to Cloud Object Storage (COS).
Audit Metadata