imessage-query
Warn
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: MEDIUMDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [DATA_EXFILTRATION]: Accesses the macOS iMessage database located at
~/Library/Messages/chat.db. This file is a highly sensitive repository of private communications. The skill's functionality relies on the user granting 'Full Disk Access' to the execution environment. - [INDIRECT_PROMPT_INJECTION]: The skill extracts and processes untrusted data from the iMessage database which could contain malicious instructions.
- Ingestion points: Reads
textandattributedBodycolumns from themessagetable inchat.dbusing thescripts/decode_attributed_body.pyscript. - Boundary markers: The script produces pipe-delimited output (
timestamp|sender|text) but does not implement sanitization or clear instructional boundaries for the extracted content. - Capability inventory: The skill has access to
Bash,Write,Read,Grep, andGlobtools. Malicious content within a message could potentially influence the agent to perform unauthorized file or command operations. - Sanitization: The skill performs no sanitization or escaping of the extracted message content before presenting it to the agent context.
- [EXTERNAL_DOWNLOADS]: The documentation and the
scripts/decode_attributed_body.pyscript (via PEP 723 metadata) recommend the installation of thepytypedstreampackage from PyPI. While this is a functional requirement for the 'Tier 1' decoder, it involves downloading code from an external, non-whitelisted source.
Audit Metadata