bezalel-imessage

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes inbound iMessage texts (imessage.received events) which may originate from untrusted external sources, specifically guest users in group chats.
  • Ingestion points: Inbound texts are delivered via the imessage.received payload, including fields for text and content arms.
  • Boundary markers: The skill documentation provides explicit security guidance for the agent, stating that when senderIsOwner is false, it should be conservative and not allow guests to approve spending, change settings, or access private context.
  • Capability inventory: The skill provides tools to send messages (imessage__send), attachments (imessage__send_attachment), and polls (imessage__send_poll), as well as the ability to react to messages (imessage__react).
  • Sanitization: The skill relies on the agent to interpret the senderIsOwner flag and follow the provided behavioral guidelines; no automated sanitization of incoming text content is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:56 PM
Security Audit — agent-trust-hub — bezalel-imessage