imsg
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
imsgCLI tool to interact with the macOS Messages application and system services through shell commands. - [DATA_EXFILTRATION]: The skill provides access to sensitive personal data by allowing the agent to read private iMessage and SMS history via
imsg historyandimsg chats. This functionality grants the agent access to the contents of the user's message database. - [PRIVILEGE_ESCALATION]: The skill explicitly requires high-level system permissions, including 'Full Disk Access' and 'Automation' for Messages.app, to function on macOS. These permissions grant the underlying process broad access to the file system and control over other applications.
- [INDIRECT_PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection attacks where an external party could send a message containing instructions designed to manipulate the agent's behavior.
- Ingestion points: Incoming message content retrieved through
imsg historyor monitored in real-time viaimsg watch(SKILL.md). - Boundary markers: The skill includes 'Safety Rules' requiring user confirmation, but lacks technical delimiters or markers to separate untrusted message content from the agent's instructions.
- Capability inventory: The agent has the capability to send new messages (
imsg send) and read message history across all chats. - Sanitization: There is no evidence of filtering or sanitization of message content before it is processed by the agent.
Audit Metadata