Back to skill

Security audit

xihe-jianmu-ipc

Security checks for vulnerabilities and agentic risk

Overview

The package is a plausible IPC hub and mostly matches its description, but it includes invasive helper code (a script that patches another package's CLI) and the SKILL.md / metadata omit some environment/credential uses—this mismatch and the ability to spawn/patch processes warrants caution.

This package is an actual IPC hub implementation and largely does what it claims, but there are red flags you should consider before installing or running it: 1) bin/patch-channels.mjs modifies the globally installed '@anthropic-ai/claude-code' cli.js to skip a warning — this mutates other software on your machine and is unexpected for an IPC hub. Don't run that script unless you trust the source and understand the change. 2) The code reads/uses several environment variables (IPC_AUTH_TOKEN, OPENCLAW_TOKEN, IPC_CHANNEL_URL) even though SKILL.md declares none — review and set tokens carefully; treat IPC_AUTH_TOKEN and OPENCLAW_TOKEN as sensitive. 3) channel-server can POST incoming messages to an arbitrary IPC_CHANNEL_URL (potential data exfiltration) — do not set that to an external endpoint unless intended. 4) The MCP server can spawn new sessions/processes; audit spawnSession behavior (it can launch other programs) and consider running the hub in a sandbox or isolated environment first. 5) If you plan to install, review the package source locally (especially bin/patch-channels.mjs and spawn-related code), pin the npm package version, and run with IPC_AUTH_TOKEN set to a strong secret. If you are unsure, run the hub in a disposable VM/container rather than on a production workstation.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access, suspicious.potential_exfiltration

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
bin/patch-channels.mjs:13

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
mcp-server.mjs:288

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
bin/jianmu.mjs:22

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
channel-server.mjs:24

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
hub.mjs:24

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
mcp-server.mjs:37

File read combined with network send (possible exfiltration).

Warn
Code
suspicious.potential_exfiltration
Location
channel-server.mjs:18

File read combined with network send (possible exfiltration).

Warn
Code
suspicious.potential_exfiltration
Location
mcp-server.mjs:22