osint

Pass

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a comprehensive security and ethics framework (the 'Four Gates') that mandates lawful basis, identity disambiguation, source independence, and confidence grading before any findings are reported to the user.
  • [EXTERNAL_DOWNLOADS]: The included scripts (domain-footprint.sh, verify-domain.sh) fetch intelligence data from well-known technology services including crt.sh (Certificate Transparency logs) and the Internet Archive's Wayback Machine. These operations are restricted to passive reconnaissance and do not involve active probing of target infrastructure.
  • [COMMAND_EXECUTION]: The skill uses utility scripts to perform standard network lookups (via dig, whois, and curl). These scripts are used to gather publicly available information and are designed with safeguards, such as connectivity checks and non-disclosure of environment variables/API keys in logs.
  • [PROMPT_INJECTION]: No malicious instructions attempting to bypass safety filters or override agent behavior were detected. The instructions are focused on adherence to OSINT best practices and ethical guidelines.
  • [DATA_EXFILTRATION]: While the skill utilizes API keys for various OSINT services (e.g., Shodan, GitHub), it does not hardcode these secrets or exfiltrate them. The capability-checking script (osint-capabilities.sh) explicitly validates the presence of keys without printing their values.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 18, 2026, 04:03 AM
Security Audit — agent-trust-hub — osint