bezalel-imessage
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes inbound iMessage texts (
imessage.receivedevents) which may originate from untrusted external sources, specifically guest users in group chats. - Ingestion points: Inbound texts are delivered via the
imessage.receivedpayload, including fields fortextandcontentarms. - Boundary markers: The skill documentation provides explicit security guidance for the agent, stating that when
senderIsOwneris false, it should be conservative and not allow guests to approve spending, change settings, or access private context. - Capability inventory: The skill provides tools to send messages (
imessage__send), attachments (imessage__send_attachment), and polls (imessage__send_poll), as well as the ability to react to messages (imessage__react). - Sanitization: The skill relies on the agent to interpret the
senderIsOwnerflag and follow the provided behavioral guidelines; no automated sanitization of incoming text content is described.
Audit Metadata