osint-technique

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill includes a utility script (scripts/h1_reference.py) that queries HackerOne's official GraphQL API to retrieve community-validated security reports for research and impact framing. This interaction targets a well-known service and is restricted to public data.
  • [INDIRECT_PROMPT_INJECTION]: As an OSINT tool, this skill is designed to ingest and analyze vast amounts of untrusted data from external sources, including web pages, social media, and breach databases. While this provides a surface for indirect prompt injection via adversarial content, the skill emphasizes human-led synthesis, reporting, and evidence archival rather than autonomous action on the ingested data.
  • [SAFE]: The skill provides extensive documentation on passive reconnaissance, operational security (OpSec), and reproducible evidence logging. The included scripts (scripts/secret_scan.py and scripts/h1_reference.py) use standard libraries for scanning text and querying public APIs, serving as benign research aids for security analysts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 10:40 PM
Security Audit — agent-trust-hub — osint-technique