automating-messages
Warn
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: MEDIUMDATA_EXFILTRATIONPERSISTENCECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [DATA_EXFILTRATION]: The skill accesses the sensitive Messages database located at '~/Library/Messages/chat.db'. This file contains the complete history of iMessage and SMS conversations, including message text, attachments, and timestamps. The skill's ability to read this history combined with its ability to send messages creates a primary data exfiltration surface.
- [PERSISTENCE]: The skill provides instructions for creating background daemons using 'launchd' via configuration files in '~/Library/LaunchAgents/'. This allows the skill's monitoring scripts to run automatically and persistently across user sessions.
- [PRIVILEGE_ESCALATION]: Documentation directs the user or agent to grant 'Full Disk Access' and 'Accessibility' permissions. Full Disk Access is a high-privilege permission required to read the Messages database, but it also exposes almost all other user data on the system to the executing script.
- [COMMAND_EXECUTION]: The skill uses 'doShellScript' to execute arbitrary bash and sqlite3 commands. It also employs 'System Events' for UI scripting, including simulated keystrokes (Command+V and Enter) to automate the sending of attachments through the Messages application UI.
- [INDIRECT_PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection by reading untrusted message content. (1) Ingestion Points: '~/Library/Messages/chat.db' accessed via 'sqlite3'. (2) Boundary Markers: None; there are no instructions to delimit or ignore instructions found within message text. (3) Capability Inventory: Access to 'doShellScript', 'Messages.send', and UI automation. (4) Sanitization: None; external content is processed as raw text for history or polling.
- [DYNAMIC_EXECUTION]: The skill dynamically constructs shell and SQL strings at runtime to be executed via 'doShellScript' and 'sqlite3', which can be influenced by the handles or search parameters provided during execution.
Audit Metadata