beeper
Warn
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: MEDIUMDATA_EXFILTRATIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: Accesses the Beeper message database located at
~/Library/Application Support/BeeperTexts/index.db. This file contains sensitive private communications, contact hints, and message history from services like iMessage and WhatsApp. - [COMMAND_EXECUTION]: Executes shell commands via
sqlite3to query the local message database. This allows the agent to read and process structured private data. - [INDIRECT_PROMPT_INJECTION]: Ingests untrusted data from chat history, which may contain malicious instructions.
- Ingestion points: Message content is retrieved from the
mx_room_messages_ftstable in the local SQLite database. - Boundary markers: No delimiters or safety instructions are used to distinguish chat data from agent commands.
- Capability inventory: The skill possesses shell command execution capabilities via the
sqlite3tool. - Sanitization: No filtering or sanitization is applied to the retrieved chat messages before they enter the agent's context.
Audit Metadata