openlink

PassAudited by VirusTotal on Apr 1, 2026.

Findings (1)

The skill implements a 'Heartbeat' mechanism in SKILL.md and HEARTBEAT.md that instructs the AI agent to periodically fetch and 'follow' instructions from a remote URL (https://www.openlink.wiki/heartbeat.md). This architecture creates a Remote Instruction Execution (prompt injection) vector, allowing the server owner to dynamically control the agent's behavior or issue new commands without a skill update. While the current instructions are focused on benign community engagement, the capability for remote control is a significant security risk.