recon-osint
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from untrusted external sources, creating a potential surface for indirect prompt injection attacks.
- Ingestion points: External data enters the agent's context through tools like
github-search,shodan, andcensysas described in the methodology inSKILL.md. - Boundary markers: The instructions do not define clear delimiters or provide the agent with warnings to ignore instructions that might be embedded within the retrieved OSINT data (e.g., within public code comments or metadata).
- Capability inventory: The skill utilizes various search and scanning tools to collect information which is then interpreted by the model.
- Sanitization: The skill lacks explicit instructions for sanitizing or filtering external content before it is processed by the agent.
Audit Metadata