imsg-rpc
Fail
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: HIGHPRIVILEGE_ESCALATIONDATA_EXFILTRATIONPERSISTENCECOMMAND_EXECUTIONCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [PRIVILEGE_ESCALATION]: The skill instructs the agent/user to install a locally generated certificate as a trusted root authority using the command
security add-trusted-cert -d -r trustRoot. This allows the system to trust any binary signed by the generated certificate, bypassing standard macOS code signing protections. - [PRIVILEGE_ESCALATION]: The skill provides detailed steps to grant 'Full Disk Access' (FDA) to a custom binary. FDA allows a process to bypass Transparency, Consent, and Control (TCC) protections to access sensitive user folders like Mail, Messages, and Safari data.
- [DATA_EXPOSURE]: The architecture relies on direct SQLite reads of the iMessage database (
~/Library/Messages/chat.db), which contains the user's entire message history. - [DATA_EXPOSURE]: The skill provides instructions for querying the macOS system privacy database (
/Library/Application Support/com.apple.TCC/TCC.db) usingsqlite3, which is a sensitive administrative action. - [CREDENTIALS_UNSAFE]: The instructions include a hardcoded password (
imsg123) for both exporting a PKCS12 certificate and importing it into the system keychain viasecurity import. - [PERSISTENCE]: The skill configures and manages a
launchdagent (~/Library/LaunchAgents/com.joel.imsg-rpc.plist) to ensure the bridge binary runs automatically and persists across sessions. - [COMMAND_EXECUTION]: The skill requires the execution of multiple high-impact system commands including
security,openssl, andlaunchctlto modify the security posture of the host machine. - [INDIRECT_PROMPT_INJECTION]: The skill provides instructions to monitor system logs (
tail -f /tmp/joelclaw/gateway.log) which likely contain content from incoming iMessage traffic. This creates a vulnerability surface where malicious external messages could influence the agent's behavior. - Ingestion points: Reading logs from
/tmp/joelclaw/gateway.loginSKILL.md. - Boundary markers: None present; the log output is piped directly to
greporrgand displayed to the agent context. - Capability inventory:
launchctl(service control),security(keychain/cert manipulation),openssl(cert generation),sqlite3(database access). - Sanitization: No evidence of sanitization or filtering of log content before it is processed by the agent.
Recommendations
- AI detected serious security threats
Audit Metadata