send-imessage

Security checks across malware telemetry and agentic risk

Overview

This skill does what it says: it lets an agent send iMessages from a Mac, with real outbound-message risk but no hidden install, persistence, or unrelated behavior found.

Install only if you are comfortable letting an agent send Messages from your Mac. Before each send, require the agent to show the final phone number and exact message body, and avoid using untrusted or unsanitized text that could break AppleScript quoting.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill enables sending arbitrary message content to a phone number through Messages without requiring an explicit confirmation step or warning that content will be transmitted externally. In an agent setting, this creates a real risk of unintended outbound communication, privacy leakage, or misuse if the extracted recipient or message body is wrong or manipulated.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal