company-osint

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [NO_CODE]: The skill consists exclusively of markdown instructions and YAML configuration. It contains no executable scripts or code-based logic.
  • [PROMPT_INJECTION]: The skill describes a workflow that ingests data from untrusted external sources (e.g., public registries, social media, and GitHub), creating a surface for indirect prompt injection.
  • Ingestion points: Data is retrieved from external sources as described in Steps 2-5 of SKILL.md.
  • Boundary markers: The skill does not define specific delimiters to isolate external content.
  • Capability inventory: Capabilities are limited to data retrieval and reporting; no unsafe file-system or network operations are defined.
  • Sanitization: No sanitization or filtering logic is specified.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 09:31 AM
Security Audit — agent-trust-hub — company-osint