offensive-osint-role
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill instructions direct the agent to adopt an 'Offensive OSINT Operator' persona focused on identifying leaked credentials and facilitating harmful activities such as phishing campaigns and password spraying.
- [PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data from public records and leaked repositories, which serves as an attack surface for indirect prompt injection.
- Ingestion points: Public records, exposed Git repositories, and breached password datasets (mentioned in SKILL.md).
- Boundary markers: No delimiters or specific instructions are provided to ignore embedded commands or adversarial text within the processed data.
- Capability inventory: Identifying credentials and coordinating handoffs for phishing and password spraying actions.
- Sanitization: There is no evidence of validation or sanitization of the external content before it enters the agent context.
Audit Metadata