imsg
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructions specify the installation of an external CLI tool from a third-party Homebrew repository:
brew install steipete/tap/imsg. - [COMMAND_EXECUTION]: The skill operates by executing shell commands (
imsg chats,imsg history,imsg watch,imsg send) to read from and write to the macOS messaging system. - [PRIVILEGE_ESCALATION]: Setup requires the user to grant the terminal 'Full Disk Access' and 'Automation' permissions. These are high-privilege macOS permissions that allow the agent to read the sensitive
chat.dbdatabase and control the Messages application. - [INDIRECT_PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection by reading untrusted content from incoming messages.
- Ingestion points: Untrusted data enters the agent context through the
imsg historyandimsg watchcommands documented inSKILL.md. - Boundary markers: Absent. There are no instructions or delimiters provided to help the agent distinguish between legitimate message content and embedded malicious instructions.
- Capability inventory: The skill possesses the capability to read local files (
history), execute shell commands, and perform network-adjacent operations by sending messages (imsg send) as detailed inSKILL.md. - Sanitization: Absent. There is no evidence of content filtering, validation, or escaping of the messages read by the CLI tool.
Audit Metadata