skills/assafkip/huntkit/osint/Gen Agent Trust Hub

osint

Pass

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFE
Full Analysis
  • [COMMAND_EXECUTION]: The script extract-intake.py uses subprocess.run to call local utilities like pdftotext, pdftoppm, tesseract, and textutil for extracting text and OCR data from user-provided documents in the intake directory. The meta-ad-library-hidden-api.sh script also utilizes Node.js and the Chrome DevTools Protocol to interact with public Facebook Ad Library data.
  • [DATA_EXFILTRATION]: The skill frequently uses curl to transmit identifiers (names, emails, domains) to numerous external OSINT and search services, including Perplexity, Exa, Tavily, Apify, Jina, Parallel, Bright Data, HudsonRock, Keybase, GitHub, and LeakCheck. These operations are the primary function of the research skill.
  • [EXTERNAL_DOWNLOADS]: The documentation suggests installing external packages such as holehe via pip and building the cli-printing-press utility from a public GitHub repository to support specific scraping tasks.
  • [CREDENTIALS_UNSAFE]: The skill manages API tokens (e.g., APIFY_API_TOKEN, JINA_API_KEY) using environment variables or dedicated local configuration files like scripts/apify-api-token.txt, consistent with standard CLI development practices.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 20, 2026, 06:44 AM
Security Audit — agent-trust-hub — osint