skills/linkupplatform/openclaw/imsg/Gen Agent Trust Hub

imsg

Warn

Audited by Gen Agent Trust Hub on Aug 1, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill attempts to install a third-party binary using the Homebrew package manager from a non-official tap: steipete/tap/imsg.
  • [DATA_EXPOSURE]: The skill requires 'Full Disk Access' to read the macOS iMessage database (chat.db). This grants the agent access to all private text communications, including sensitive information like multi-factor authentication codes, personal conversations, and contact details.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external message sources via the imsg history and imsg watch commands.
  • Ingestion points: External iMessage/SMS content read through imsg history or imsg watch commands.
  • Boundary markers: None identified; the skill does not specify delimiters or instructions to ignore embedded commands within message content.
  • Capability inventory: The skill has the capability to send messages (imsg send) and read files, which could be abused if an incoming message contains instructions the agent follows.
  • Sanitization: No evidence of sanitization or filtering of the incoming message text before it is processed by the agent.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 1, 2026, 08:32 AM
Security Audit — agent-trust-hub — imsg