Back to skill

Security audit

Imsg

Security checks for vulnerabilities and agentic risk

Overview

This skill clearly explains that it reads and sends iMessage/SMS, but it installs an unpinned third-party command-line tool that would run with very sensitive macOS Messages permissions.

Install only if you trust the imsg Homebrew tap and are comfortable granting your terminal access to Messages data and permission to send messages. Prefer reviewing the dependency source and version before install, avoid broad Full Disk Access where possible, and keep manual confirmation for every send action.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:5
Finding

Unpinned Third-Party Homebrew Dependency Used with Broad Privacy Permissions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 5-14
Vulnerability Type: Supply-chain exposure through an unpinned third-party dependency
Risk Level: Medium

Vulnerable Code Snippet

yaml
metadata: {"clawdbot":{"emoji":"📨","os":["darwin"],"requires":{"bins":["imsg"]},"install":[{"id":"brew","kind":"brew","formula":"steipete/tap/imsg","bins":["imsg"],"label":"Install imsg (brew)"}]}}
---

# imsg

Use `imsg` to read and send Messages.app iMessage/SMS on macOS.

Requirements
- Messages.app signed in
- Full Disk Access for your terminal
- Automation permission to control Messages.app (for sending)

Technical Analysis

The skill installs imsg from the third-party Homebrew tap steipete/tap/imsg. The dependency declaration does not specify an immutable version, source commit, cryptographic checksum, or signature. Consequently, the code installed in the future may differ from the version that was originally reviewed.

This supply-chain exposure is amplified because the installed executable is intended to run from a terminal granted Full Disk Access and Messages.app automation permission. If the tap, formula, release infrastructure, or maintainer account were compromised, a modified package could execute with access to sensitive local data and control Messages.app.

The reviewed file does not establish that the current package is malicious. The vulnerability is the absence of integrity pinning and verification for a dependency that is expected to operate with high-impact privacy permissions.

Attack Path

  1. An attacker compromises the third-party Homebrew tap, its maintainer account, the referenced release artifact, or another component of its distribution infrastructure.
  2. The attacker modifies the formula or distributed artifact while retaining the expected package name.
  3. A user follows the skill installation metadata and installs or upgrades steipete/tap/imsg.
  4. Homebrew ...[truncated 1156 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the dependency to a specific, reviewed release rather than relying on a mutable formula reference.
  2. Record and verify a cryptographic digest for the exact release artifact before installation.
  3. Where supported, require signed releases and verify signatures against a documented, trusted maintainer key.
  4. Pin the Homebrew tap or formula source to an immutable reviewed commit and establish a controlled process for updating that pin.
  5. Document the authoritative source repository and release channel so users can detect lookalike or substituted packages.
  6. Avoid granting Full Disk Access to a general-purpose terminal. Prefer a narrowly scoped launcher or dedicated execution environment with only the permissions required for message access.
  7. Separate read and send capabilities where possible, granting Messages.app automation permission only when sending is required.
  8. Review dependency changes before upgrades and use lockfiles, internal mirrors, or approved artifact repositories where operationally feasible.
  9. Retain the existing requirement to confirm the recipient and message content before sending, and enforce that confirmation in the calling agent rather than relying solely on documentation.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.