skills/aeondave/malskill/phoneinfoga/Gen Agent Trust Hub

phoneinfoga

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the user to execute shell commands to perform phone number scans and launch a web-based dashboard.
  • Evidence: Use of phoneinfoga scan, phoneinfoga serve, and shell loops to process files.
  • [EXTERNAL_DOWNLOADS]: The skill recommends obtaining the tool via GitHub releases or by pulling a Docker image from a remote registry.
  • Evidence: docker run --rm sundowndev/phoneinfoga.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes a tool that ingests and processes data from untrusted external sources, such as Google search results and third-party APIs, which could theoretically contain instructions designed to influence the agent.
  • Ingestion points: Data retrieved from Google Dorks (LinkedIn, Facebook, etc.) and API responses from NumVerify.
  • Boundary markers: Absent. There are no instructions for the agent to use delimiters or ignore embedded instructions within search results.
  • Capability inventory: The skill utilizes shell execution, network access for OSINT, and file system writes for saving results.
  • Sanitization: Absent. The documentation does not specify methods for sanitizing or escaping the data gathered from the web before presentation or processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:56 AM
Security Audit — agent-trust-hub — phoneinfoga