skills/joelhooks/joelclaw/imsg/Gen Agent Trust Hub

imsg

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructions specify the installation of an external CLI tool from a third-party Homebrew repository: brew install steipete/tap/imsg.
  • [COMMAND_EXECUTION]: The skill operates by executing shell commands (imsg chats, imsg history, imsg watch, imsg send) to read from and write to the macOS messaging system.
  • [PRIVILEGE_ESCALATION]: Setup requires the user to grant the terminal 'Full Disk Access' and 'Automation' permissions. These are high-privilege macOS permissions that allow the agent to read the sensitive chat.db database and control the Messages application.
  • [INDIRECT_PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection by reading untrusted content from incoming messages.
  • Ingestion points: Untrusted data enters the agent context through the imsg history and imsg watch commands documented in SKILL.md.
  • Boundary markers: Absent. There are no instructions or delimiters provided to help the agent distinguish between legitimate message content and embedded malicious instructions.
  • Capability inventory: The skill possesses the capability to read local files (history), execute shell commands, and perform network-adjacent operations by sending messages (imsg send) as detailed in SKILL.md.
  • Sanitization: Absent. There is no evidence of content filtering, validation, or escaping of the messages read by the CLI tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 05:03 PM
Security Audit — agent-trust-hub — imsg