email-osint
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection attack surface (Category 8) due to its core function of ingesting and processing untrusted data from external sources.\n
- Ingestion points: Target email addresses provided by the user are used as inputs for searches across external platforms.\n
- Boundary markers: There are no explicit delimiters or specific instructions for the agent to ignore potential malicious commands embedded in the search results or tool outputs.\n
- Capability inventory: The skill workflow utilizes multiple tools including search engines (Google Dorking), CLI tools (Holehe, Maigret), and other internal OSINT modules (person-osint, username-osint, etc.).\n
- Sanitization: The instructions do not define methods for sanitizing, validating, or escaping content retrieved from external sources before it is analyzed or included in the final report.
Audit Metadata