osint

Fail

Audited by Socket on Mar 22, 2026

2 alerts found:

SecurityObfuscated File
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally coherent as an OSINT dossier builder, but its actual footprint is far beyond benign research: it directs the agent to harvest private local communications, propagate personal data across multiple third-party services and sub-agents, and recursively build actionable psychoprofiles on individuals. This is high-risk surveillance capability rather than a narrowly scoped research helper.

Confidence: 93%Severity: 94%
Obfuscated FileHIGH
assets/dossier-template.md

This is a high-risk OSINT/person-dossier template: not malware by itself, but intentionally structured to aggregate sensitive PII and private communications and to produce actionable intelligence and engagement approaches. If populated and stored or shared insecurely, it enables doxxing, social engineering, stalking, and privacy violations. Recommend treating the template as sensitive: do not populate it with real private data, avoid storing in unprotected systems, and restrict distribution. If found in a repository, flag for review and consider removal or adding strong access controls and audit logging.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 22, 2026, 01:30 PM
Package URL
pkg:socket/skills-sh/smixs%2Fosint-skill%2Fosint%2F@e54852cb80a104d3b2add8106ab32966ef748aa6