MIM Chat
PassAudited by VirusTotal on May 14, 2026.
Findings (1)
The skill provides instructions and a Node.js script to connect to a specific external chat server (`https://mol-chat-server-production.up.railway.app`) using Socket.IO. The script installs a standard npm package (`socket.io-client`) in a temporary directory and then connects, signs on, sends messages, and listens for chat events. All actions are directly aligned with the stated purpose of an instant messenger client. There is no evidence of data exfiltration, malicious execution, persistence mechanisms, prompt injection attempts against the agent, or obfuscation. The network and shell access are necessary for the skill's functionality and are used in a controlled manner with hardcoded commands.
