iMessageSAFE
A Model Context Protocol server for reading iMessage data from macOS.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A Deno monorepo containing packages for iMessage access on macOS:
- @wyattjoh/imessage - Core library for read-only iMessage database access
- @wyattjoh/imessage-mcp - Model Context Protocol (MCP) server for LLM integration
Features
- Search messages by text content, contact, or date range
- Get recent messages
- List all chats/conversations
- Get all contacts/handles
- Retrieve messages from specific chats
- Search macOS Contacts by name with iMessage handle ID correlation
Requirements
- macOS (iMessage is only available on macOS)
- Deno 2.x or later
- Read access to
~/Library/Messages/chat.db, or to a custom database configured withIMESSAGE_DB_PATH - Read access to
~/Library/Application Support/AddressBook/(for contacts search)
Packages
@wyattjoh/imessage
Core library for accessing iMessage data:
deno add @wyattjoh/imessage
import { openMessagesDatabase, searchMessages } from "@wyattjoh/imessage";
const db = await openMessagesDatabase();
const results = await searchMessages(db, { query: "hello" });
db.close();See full documentation
@wyattjoh/imessage-mcp
MCP server for LLM integration:
# Run directly from JSR deno run --allow-read --allow-env --allow-sys --allow-ffi jsr:@wyattjoh/imessage-mcp # Or install globally deno install --global --allow-read --allow-env --allow-sys --allow-ffi -n imessage-mcp jsr:@wyattjoh/imessage-mcp
For Claude Desktop app integration, add this to your claude_desktop_config.json:
{
"mcpServers": {
"imessage": {
"command": "deno",
"args": [
"run",
"--allow-read",
"--allow-env",
"--allow-sys",
"--allow-ffi",
"jsr:@wyattjoh/imessage-mcp"
]
}
}
}Custom Messages Database
Set IMESSAGE_DB_PATH to open a read-only SQLite database at another location, such as a pe
bacc164e6371OBSERVED · 2026-10-08Exposed tools (6)
6 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
get_chats | read | Get list of iMessage chats/conversations ordered by most recent activity. Returns chat GUIDs that can be used with |
get_handles | read | Get list of all contacts/handles (phone numbers, email addresses) that have sent or received iMessages. Returns handle IDs that can be used with |
get_messages_from_chat | read | Get messages from a specific chat/conversation using the chat GUID (obtained from |
get_recent_messages | read | Get the most recent iMessages across all conversations, ordered by date (newest first). CRITICAL: Results are paginated - for comprehensive analysis or complete recent activity overview, you MUST paginate through ALL results by checking |
search_contacts | read | Search for contacts by first name and optional last name. Use this FIRST when searching for messages from a specific person - it returns the phone number that can be used as the |
search_messages | read | Search iMessage messages with various filters. Use |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
bacc164e6371full audit observations/trust-audit/mcp-server/wyattjoh__imessage-2.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | bacc164e6371 | SAFE | B | 89 | first audit |
Questions
What is the iMessage MCP server?
A Model Context Protocol server for reading iMessage data from macOS.
What tools does iMessage expose?
6 in total: 6 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is iMessage safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does iMessage need?
No credential environment variables were found in its source, so it appears to need none.
How does iMessage run?
It speaks stdio, so it runs as a local process your client starts.
How current is this page?
The grade is for one exact copy of the source (bacc164e6371), read on 2026-10-08. The repository is watched and re-audited when it changes.