osint-technique
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill includes a utility script (
scripts/h1_reference.py) that queries HackerOne's official GraphQL API to retrieve community-validated security reports for research and impact framing. This interaction targets a well-known service and is restricted to public data. - [INDIRECT_PROMPT_INJECTION]: As an OSINT tool, this skill is designed to ingest and analyze vast amounts of untrusted data from external sources, including web pages, social media, and breach databases. While this provides a surface for indirect prompt injection via adversarial content, the skill emphasizes human-led synthesis, reporting, and evidence archival rather than autonomous action on the ingested data.
- [SAFE]: The skill provides extensive documentation on passive reconnaissance, operational security (OpSec), and reproducible evidence logging. The included scripts (
scripts/secret_scan.pyandscripts/h1_reference.py) use standard libraries for scanning text and querying public APIs, serving as benign research aids for security analysts.
Audit Metadata