skills/joelhooks/joelclaw/imsg-rpc/Gen Agent Trust Hub

imsg-rpc

Fail

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: HIGHPRIVILEGE_ESCALATIONDATA_EXFILTRATIONPERSISTENCECOMMAND_EXECUTIONCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PRIVILEGE_ESCALATION]: The skill instructs the agent/user to install a locally generated certificate as a trusted root authority using the command security add-trusted-cert -d -r trustRoot. This allows the system to trust any binary signed by the generated certificate, bypassing standard macOS code signing protections.
  • [PRIVILEGE_ESCALATION]: The skill provides detailed steps to grant 'Full Disk Access' (FDA) to a custom binary. FDA allows a process to bypass Transparency, Consent, and Control (TCC) protections to access sensitive user folders like Mail, Messages, and Safari data.
  • [DATA_EXPOSURE]: The architecture relies on direct SQLite reads of the iMessage database (~/Library/Messages/chat.db), which contains the user's entire message history.
  • [DATA_EXPOSURE]: The skill provides instructions for querying the macOS system privacy database (/Library/Application Support/com.apple.TCC/TCC.db) using sqlite3, which is a sensitive administrative action.
  • [CREDENTIALS_UNSAFE]: The instructions include a hardcoded password (imsg123) for both exporting a PKCS12 certificate and importing it into the system keychain via security import.
  • [PERSISTENCE]: The skill configures and manages a launchd agent (~/Library/LaunchAgents/com.joel.imsg-rpc.plist) to ensure the bridge binary runs automatically and persists across sessions.
  • [COMMAND_EXECUTION]: The skill requires the execution of multiple high-impact system commands including security, openssl, and launchctl to modify the security posture of the host machine.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides instructions to monitor system logs (tail -f /tmp/joelclaw/gateway.log) which likely contain content from incoming iMessage traffic. This creates a vulnerability surface where malicious external messages could influence the agent's behavior.
  • Ingestion points: Reading logs from /tmp/joelclaw/gateway.log in SKILL.md.
  • Boundary markers: None present; the log output is piped directly to grep or rg and displayed to the agent context.
  • Capability inventory: launchctl (service control), security (keychain/cert manipulation), openssl (cert generation), sqlite3 (database access).
  • Sanitization: No evidence of sanitization or filtering of log content before it is processed by the agent.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 23, 2026, 05:03 PM
Security Audit — agent-trust-hub — imsg-rpc