I got the impression from the code that this operates directly on whatever sqlite db iMessage actually uses. Is this right? If so, it's probably worth considering just making a copy, or including a script that makes the copy, when sudo'd. That way you don't need the permanent permission and there's no chance of accidentally messing up an important bit of user data. And paranoid people will probably feel better about not having a live local webserver that's poking around their personal messages.