imsg

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [PRIVILEGE_ESCALATION]: The skill requires 'Full Disk Access', a high-privilege macOS permission that allows the agent to bypass standard sandbox restrictions and access sensitive user data directories including mail, browser history, and backups. Evidence: 'Full Disk Access for your terminal'.
  • [INDIRECT_PROMPT_INJECTION]: The skill reads untrusted external data from incoming messages, creating a vulnerability surface where malicious instructions embedded in messages could influence the agent's behavior.
  • Ingestion points: 'imsg history', 'imsg watch' in SKILL.md.
  • Boundary markers: Absent.
  • Capability inventory: Ability to execute shell commands and send outgoing messages.
  • Sanitization: Absent; content is processed directly via the CLI tool.
  • [COMMAND_EXECUTION]: The skill relies on an external CLI utility to perform its core functions, which the agent is instructed to execute. Evidence: 'imsg chats', 'imsg history', 'imsg send'.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 07:45 PM
Security Audit — agent-trust-hub — imsg