imessage
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEDATA_EXFILTRATIONCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [DATA_EXFILTRATION]: The skill accesses the sensitive macOS Messages database located at
~/Library/Messages/chat.dbto read message history and metadata. It also facilitates reading local file system paths to upload and send attachments. - [COMMAND_EXECUTION]: The local iMessage kit uses AppleScript (
osascript) to programmatically control the Messages app for sending texts and attachments. - [PRIVILEGE_ESCALATION]: To operate locally, the skill instructs users to grant 'Full Disk Access' permissions to the process (terminal or IDE) within macOS System Settings, allowing it to bypass standard file system sandbox restrictions for the Messages database.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external data from incoming iMessages, which could contain malicious instructions.
- Ingestion points: Inbound message handlers in
references/local-v3.md(onIncomingMessage,onDirectMessage) andreferences/hosted-v2.md(subscribeEvents). - Boundary markers: The
SKILL.mdfile contains a 'Common invariants' section explicitly warning developers to treat message text, attachments, and URLs as untrusted data and to avoid interpolating them into system prompts or commands. - Capability inventory: The skill possesses capabilities for reading local files, performing network uploads to hosted APIs, and sending automated replies.
- Sanitization: While the documentation mandates sanitization as a best practice, the provided code snippets do not implement automated filtering or escaping of incoming text.
- [EXTERNAL_DOWNLOADS]: The skill references package manifests and documentation from vendor-controlled domains and well-known services.
- Fetches package manifests from
unpkg.com. - Links to documentation and resources on
photon.codesand GitHub repositories under thephoton-hqorganization.
Audit Metadata