osint-investigation

Pass

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads structured data and records from numerous established public repositories and well-known services, including the SEC, US Treasury, USAspending, Senate Lobbying Disclosure portal, ICIJ Offshore Leaks database, OpenCorporates, CourtListener, GDELT, Internet Archive, and Wikimedia. These operations are fundamental to the skill's primary research purpose and are conducted over HTTPS targeting official domains.
  • [COMMAND_EXECUTION]: The framework includes a collection of Python scripts designed to be executed via a terminal tool. These scripts perform deterministic tasks such as data fetching, entity resolution (name matching), and statistical timing analysis using the Python standard library.
  • [DATA_EXPOSURE]: The skill manages API authentication via environment variables (e.g., OPENCORPORATES_API_TOKEN, COURTLISTENER_TOKEN) or command-line arguments. This is a standard and secure approach for managing credentials in developer tools, with no evidence of hardcoded secrets or unauthorized exfiltration of local sensitive files.
  • [PROMPT_INJECTION]: The skill contains clear instructional guidelines that emphasize evidence-based reasoning and caution against making unverified assertions. It does not contain patterns attempting to bypass agent safety filters or override system instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 13, 2026, 06:31 AM
Security Audit — agent-trust-hub — osint-investigation