imessage-query

Warn

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [DATA_EXFILTRATION]: Accesses the macOS iMessage database located at ~/Library/Messages/chat.db. This file is a highly sensitive repository of private communications. The skill's functionality relies on the user granting 'Full Disk Access' to the execution environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill extracts and processes untrusted data from the iMessage database which could contain malicious instructions.
  • Ingestion points: Reads text and attributedBody columns from the message table in chat.db using the scripts/decode_attributed_body.py script.
  • Boundary markers: The script produces pipe-delimited output (timestamp|sender|text) but does not implement sanitization or clear instructional boundaries for the extracted content.
  • Capability inventory: The skill has access to Bash, Write, Read, Grep, and Glob tools. Malicious content within a message could potentially influence the agent to perform unauthorized file or command operations.
  • Sanitization: The skill performs no sanitization or escaping of the extracted message content before presenting it to the agent context.
  • [EXTERNAL_DOWNLOADS]: The documentation and the scripts/decode_attributed_body.py script (via PEP 723 metadata) recommend the installation of the pytypedstream package from PyPI. While this is a functional requirement for the 'Tier 1' decoder, it involves downloading code from an external, non-whitelisted source.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 16, 2026, 12:15 AM
Security Audit — agent-trust-hub — imessage-query