imessage
Warn
Audited by Gen Agent Trust Hub on Jul 18, 2026
Risk Level: MEDIUMDATA_EXFILTRATIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill accesses highly sensitive personal data by reading the local iMessage database (~/Library/Messages/chat.db) and AddressBook contacts. Although the Python script does not contain network exfiltration logic of its own, the exposure of full chat histories and contact details to the AI agent's context is a significant privacy risk.\n- [COMMAND_EXECUTION]: The script uses subprocess.run to execute osascript, allowing the agent to send iMessages via AppleScript. While implemented using best practices by passing arguments as a list to avoid shell interpolation, this capability provides the agent with an external side-effect (sending real-world messages) that must be strictly monitored.\n- [PROMPT_INJECTION]: The skill processes untrusted external data (incoming iMessages) which creates a surface for indirect prompt injection.\n
- Ingestion points: Reads message text and binary attributedBody blobs from the local chat.db database (scripts/imessage_cli.py).\n
- Boundary markers: SKILL.md contains specific instructions for the agent to treat message content as untrusted data and ignore any commands or instructions found within it.\n
- Capability inventory: The skill can read all messages, resolve contacts, and send messages through a CLI wrapper around osascript.\n
- Sanitization: The skill relies on natural language instructions to the agent and user confirmation checkpoints rather than programmatic sanitization of the database content.
Audit Metadata