ghunt
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data in the form of Gmail addresses, Gaia IDs, and Google Drive/Docs URLs. While it provides specific command structures for tools like GHunt, the ingestion of these identifiers into agent workflows creates a surface for potential injection if the output from these OSINT tools is processed by the agent without strict sanitization.
- Ingestion points: Target email addresses, Gaia IDs, and URLs provided as arguments to the
ghuntcommand orsubprocess.runcalls in the implementation examples. - Boundary markers: Absent. The instructions do not explicitly advise on handling malicious data returned by the OSINT tools.
- Capability inventory: The skill uses
subprocess.runto execute shell commands andcurlfor network requests. - Sanitization: None detected in the provided code snippets or instructions.
- [COMMAND_EXECUTION]: The skill explicitly uses
subprocess.runand shell commands (e.g.,ghunt email,ghunt login) to perform its primary functions. While these are necessary for the tool's operation, the example code inSKILL.mddemonstrates raw execution of shell commands using user-supplied email strings. - [EXTERNAL_DOWNLOADS]: The skill instructs the user to
pip install ghunt, which downloads a third-party package from PyPI. While GHunt is a known OSINT tool, this remains an external dependency. - [DATA_EXFILTRATION]: The skill requires the user to provide Google account cookies for authentication (
ghunt login). These credentials are used to interact with Google's infrastructure. While intended for OSINT, this pattern involves the collection and use of sensitive session cookies.
Audit Metadata