Skip to content
CAI
Software that uses CAICheck a score

openclaw/imsg

54.2

Adequate · 1 October 2026

20.6k

lines of production code

Swift

primary language

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a Swift-based command-line interface and RPC server for managing iMessage and SMS interactions on macOS, with limited Linux support. It provides capabilities for sending messages, managing chat groups, handling reactions and polls, and querying message history through a hardened IPC bridge to the Messages app. The tool focuses on secure contact resolution and attachment handling while exposing structured data via JSON output.

How it got here

2025 — Initial scaffolding and core feature implementation

9 changes.

This period established the project's foundational infrastructure, including Swift Package Manager configuration, build scripts, and security-hardened core modules for IPC and contact resolution. It introduced the primary CLI and RPC interfaces for managing iMessage and SMS interactions, enabling comprehensive chat, message, and attachment operations. The work also included essential macOS entitlements, privacy declarations, and initial test coverage to support the new secure communication bridge.

2026 — IMsg bridge v2 and test expansion

4 changes.

The project introduced a hardened v2 bridge helper architecture with enhanced security, new messaging features like polls and stickers, and improved stability. This release was accompanied by a significant expansion of test coverage, including comprehensive validation for CLI commands, bridge integration, and Linux-specific core messaging components.

Features

Introduce IMCore bridge CLI commands for chat and message management

This change adds a new set of CLI commands in \Sources/imsg/Commands\ that interact with the IMCore bridge (requiring \imsg launch\ with SIP disabled) to manage iMessage chats and messages. Users can now create chats (\chat-create\), manage group properties like names and photos (\chat-name\, \chat-photo\), and modify participants (\chat-add-member\, \chat-remove-member\). It also introduces message manipulation commands including sending attachments (\send-attachment\), editing (\edit\), unsending (\unsend\), deleting (\delete-message\), and sending tapback reactions (\tapback\). Additionally, it provides commands for inspecting chat backgrounds (\chat-background\), listing recent conversations (\chats\), viewing message history (\history\), and checking account status (\account\).

Sources/imsg/Commands · high confidence

Introduce secure, cross-platform IMsgCore foundation with hardened IPC and contact resolution

This change establishes the core \IMsgCore\ module, replacing previous ad-hoc implementations with a structured, secure foundation. It adds a robust contact resolution system that supports both native macOS Contacts and a fallback direct-read of the AddressBook SQLite store (for environments like SSH without Contacts framework access). Message delivery is hardened via a new \BridgeLaunchCoordinator\ that serializes Messages.app launches and enforces strict security on IPC paths (rejecting symlinks, enforcing 0700/0600 permissions). The module also introduces secure attachment handling via \AttachmentSource\ (using \O\_NOFOLLOW\ and \openat\ to prevent symlink attacks) and bounded external process execution for AppleScript and FFmpeg conversions, ensuring no hangs or unbounded resource usage.

Sources/IMsgCore · high confidence

Introduce structured CLI and RPC interfaces for iMessage management

The imsg module now provides a structured command-line interface and an RPC server for interacting with iMessage and SMS data. Users can now access detailed message metadata in JSON output, including thread originator GUIDs, reply context (text and sender), and native poll events. The new CLI supports commands for sending messages, managing reactions, and querying chat history, while the RPC layer exposes methods for real-time event watching, message sending with tracked IDs, and poll interactions. Chat targeting is now more robust, supporting resolution by chat ID, identifier, or GUID, and allowing recipient names to be resolved via the system Contacts framework. Attachment display and poll voting are now handled with dedicated logic, providing clearer output for attachments and detailed snapshots of poll selections.

Sources/imsg · high confidence

Introduce v2 bridge helper with hardened security and new messaging capabilities

The IMsgHelper module has been restructured into a new v2 bridge architecture that replaces the legacy single-file IPC with a secure, queue-based directory system. This update hardens security by enforcing 0700 permissions on IPC directories and rejecting any file paths that traverse symbolic links, preventing potential data exfiltration. Functionally, the bridge now supports sending native iMessage polls (including votes and unvotes), stickers, and rich links, while also enabling Name & Photo sharing features. The bootstrap process has been adjusted to delay initialization on the main queue to ensure stability on macOS 26, and attachment staging is now properly scoped to chat GUIDs to ensure reliable delivery.

Sources/IMsgHelper · high confidence

New build and documentation site scripts

Added a suite of new scripts to support the project's build and documentation workflows. The \build-universal.sh\ script now handles macOS universal binaries, explicitly including the arm64e architecture slice for the bridge helper to ensure compatibility with macOS 26 Messages. A new \build-linux.sh\ script enables static Linux releases using Swift 6.4's native build system. Documentation is now built via \build-docs-site.mjs\, which generates a static site with a table of contents, syntax highlighting, and a dark mode theme, and includes a \llms.txt\ index for AI agents. Supporting scripts include \patch-deps.sh\ to fix dependency bundle lookups and privacy manifests, \generate-version.sh\ to produce version metadata, and \check-linux.sh\ to validate the Linux build in Docker.

scripts · high confidence

Behavioural changes

Add Info.plist with usage descriptions for Messages and Contacts

The imsg resource bundle now includes an Info.plist file that declares the app's bundle identifiers and specifies usage descriptions for NSAppleEvents and NSContacts. This ensures the application properly requests permission to send messages via Messages.app and resolve contact names for conversations, addressing previous missing privacy declarations.

Sources/imsg/Resources · high confidence

Added macOS entitlements for Apple Events and Address Book access

A new entitlements file (imsg.entitlements) has been added to the Resources directory, granting the application permissions to access Apple Events for automation and to read data from the user's Address Book. This change enables the app to resolve contact names and interact with system automation features on macOS.

Resources · high confidence

Test coverage

Added Linux-specific test suite for core messaging components; Added comprehensive test coverage for IMsgCore core components; Added tests for iMessage bridge helper ownership, chat creation, and message identity; Expanded test coverage for CLI commands and bridge integration.

Dependencies

Initial Swift Package Manager configuration for imsg

The project now uses Swift Package Manager for dependency management and build configuration. The package defines a core library (IMsgCore) and a CLI executable (imsg), targeting macOS 14 and Linux. It integrates Commander for CLI parsing, SQLite.swift for database access, CSQLite for Linux compatibility, and PhoneNumberKit (version 5.0.11) for phone number normalization.

(dependencies) · high confidence

Housekeeping

Initial repository scaffolding and configuration

The repository is initialized with core configuration files including a SwiftLint configuration, a Makefile for build and test automation, a Crabbox infrastructure definition, and a comprehensive changelog documenting versions from 0.1.0 through 0.15.10. The project is established as a Swift 6 CLI tool for iMessage/SMS interaction, with the version set to 0.15.10 and copyright updated to 2026.

(repo-wide) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 60 → 54 (-5.9)
  • Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.

Lenses

  • Code Health 82 → 83 (+1.0)
  • Architecture 99 → 96 (-2.5)
  • Maturity 65 → 61 (-3.5)
  • Readiness 49 → 41 (-8.4)
  • Security 65 → 70 (+4.5)
  • Performance 62 (new)

Resolved (10)

  • Dependency hygiene PARTLY measured — SwiftPM pinning read, dependency currency NOT established
  • Documentation: no architecture or design documentation (README.md)
  • Documentation: no installation or build instructions (docs/README.md)
  • Documentation: no usage examples (docs/README.md)
  • Duplicated block (8–9 lines × 2) (Sources/imsg/Commands/CompletionsCommand.swift)
  • High: security finding (details withheld)
  • Hotspot: Sources/IMsgCore/StickerAsset.swift (Sources/IMsgCore/StickerAsset.swift)
  • Hotspot: Sources/imsg/Commands/LaunchCommand.swift (Sources/imsg/Commands/LaunchCommand.swift)
  • Off-boarding risk: anonymized user #1
  • Repeated repair: Sources/imsg/RPCServer+Support.swift (Sources/imsg/RPCServer+Support.swift)

New (153)

  • AttachmentDisplay.swift.pollDisplayText (cognitive 25) (Sources/imsg/AttachmentDisplay.swift)
  • Duplicated block (5 lines × 2) (Sources/IMsgCore/MessageStore+Attachments.swift)
  • Duplicated block (8 lines × 2) (Sources/imsg/Commands/CompletionsCommand.swift)
  • Excessive fragmentation of the chatInfo method. There are five distinct overloads with similar intents (retrieving chat info) but different lookup keys (ID, Target, Identifier, GUID) and varying parameter lists. This forces callers to know the exact key type to use the correct overload.
  • Inconsistent method naming and signature structure for similar RPC operations. Two overloads of invoke differ only by a timeout parameter, while a third method invokeWithoutLaunching performs a similar action but has a distinct name and signature, breaking the pattern of optional parameters.
  • Inconsistent pagination and filtering API. messages uses a limit-based approach with optional filtering, while messagesAfter uses cursor-based pagination (afterRowID) but lacks filtering. messagesAfterPage returns a wrapper type instead of a simple array, breaking consistency with the other messages methods.
  • Inconsistent return types for reactions. One overload takes an array of Messages and returns a dictionary mapping ID to reactions, while the other takes a single Int64 (likely a message ID) and returns a flat array. This forces callers to handle different data structures based on input type.
  • Low coverage: Sources/IMsgCore/AppleScriptSendTransport.swift (Sources/IMsgCore/AppleScriptSendTransport.swift)
  • Low coverage: Sources/IMsgCore/AttachmentResolver.swift (Sources/IMsgCore/AttachmentResolver.swift)
  • Low coverage: Sources/IMsgCore/AttachmentSource.swift (Sources/IMsgCore/AttachmentSource.swift)
  • Low coverage: Sources/IMsgCore/AudioMessagePreparer.swift (Sources/IMsgCore/AudioMessagePreparer.swift)
  • Low coverage: Sources/IMsgCore/BridgeFailureClassifier.swift (Sources/IMsgCore/BridgeFailureClassifier.swift)
  • Low coverage: Sources/IMsgCore/BridgeHelperLocator.swift (Sources/IMsgCore/BridgeHelperLocator.swift)
  • Low coverage: Sources/IMsgCore/BridgeLaunchCoordinator.swift (Sources/IMsgCore/BridgeLaunchCoordinator.swift)
  • Low coverage: Sources/IMsgCore/ContactResolver.swift (Sources/IMsgCore/ContactResolver.swift)
  • Low coverage: Sources/IMsgCore/DeliveryFailure.swift (Sources/IMsgCore/DeliveryFailure.swift)
  • Low coverage: Sources/IMsgCore/DirectParticipantTarget.swift (Sources/IMsgCore/DirectParticipantTarget.swift)
  • Low coverage: Sources/IMsgCore/Errors.swift (Sources/IMsgCore/Errors.swift)
  • Low coverage: Sources/IMsgCore/IMCoreBridge.swift (Sources/IMsgCore/IMCoreBridge.swift)
  • Low coverage: Sources/IMsgCore/IMsgBridgeClient.swift (Sources/IMsgCore/IMsgBridgeClient.swift)
  • …and 133 more

Changes since last survey

  • 19 commits — 9 feature/other, 10 fixes

By area

  • (root) — 13 commits
  • Sources/IMsgHelper — 2 commits
  • Sources/imsg — 2 commits
  • .github/workflows — 1 commit
  • Sources/IMsgCore — 1 commit

Notable commits

  • fix: build(deps): fix phone normalization denial of service and refresh toolchains (#313)
  • fix: fix: confirm outgoing standard tapbacks before reporting success (#312)
  • fix: fix: keep native threaded replies visible in Messages (#306)
  • fix: fix: keep watch delivery responsive during Contacts refreshes (#308)
  • fix: fix: navigate directly to standard tapback conversations (#317)
  • fix: fix: resolve exact group identifiers in bridge sends (#325)
  • fix: fix: resolve replies outside the loaded transcript (#326)
  • fix: fix: restore static Linux release packaging for 0.15.8 (#315)
  • fix: fix: verify canonically equivalent sent text (#321)
  • fix: fix: wait for attachment-only send receipts (#329)
  • change: build(deps): update PhoneNumberKit to 5.0.11 (#327)
  • change: chore: open next unreleased section (#310)
  • change: chore: open next unreleased section (#316)
  • change: chore: open next unreleased section (#319)
  • change: chore: prepare 0.15.6 release (#309)
  • change: chore: prepare 0.15.7 release (#314)
  • change: chore: prepare 0.15.9 release (#318)
  • change: chore: prepare imsg 0.15.10 (#330)
  • change: ci: allow manual validation of release commits (#331)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

openclaw/imsg was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 1 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 640f58f4f80220b10082eafe4d725049fe2acb77 — the exact code this score is about.
  • Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.