imsg

Fail

Audited by Socket on Feb 28, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The provided fragment documents a legitimate CLI for controlling Messages.app that necessarily requires high-risk macOS permissions (Full Disk Access and Automation). The security concerns are primarily supply-chain and privacy-related: obtaining the binary from a third-party Homebrew tap without checksums/signatures, combined with the broad access the binary requires, creates a realistic risk of data exposure or misuse if the binary were compromised or malicious. There is no explicit evidence of malicious code in the README itself, but absence of source or network transparency prevents ruling out exfiltration. Recommendations: audit the Homebrew formula and binary before installation, verify checksums/signatures or build from source if possible, grant Full Disk Access and Automation only to a verified executable, and monitor network activity from the binary post-installation.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 28, 2026, 08:22 PM
Package URL
pkg:socket/skills-sh/insight68%2Fskills%2Fimsg%2F@2d461b7f67e29bfc2e120100e36233b457f52d9f