osint-recon-automation

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process large volumes of untrusted data from various external sources as part of its OSINT workflow, which creates a potential surface for indirect prompt injection attacks.\n
  • Ingestion points: Data is retrieved from GitHub, public search engines (Shodan, Censys), certificate transparency logs (crt.sh), and web archives (waybackurls, gau) as specified in the Recon Workflow section of SKILL.md.\n
  • Boundary markers: There are no specific instructions or delimiters provided to guide the agent in ignoring instructions that might be embedded in the fetched reconnaissance data.\n
  • Capability inventory: The skill's description implies the agent will perform network operations, write output files (e.g., assets.jsonl, report.md), and execute various third-party command-line tools.\n
  • Sanitization: The provided instructions do not include any measures for sanitizing or filtering the content retrieved from external sources before it is processed.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 09:20 PM
Security Audit — agent-trust-hub — osint-recon-automation