email-osint

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection attack surface (Category 8) due to its core function of ingesting and processing untrusted data from external sources.\n
  • Ingestion points: Target email addresses provided by the user are used as inputs for searches across external platforms.\n
  • Boundary markers: There are no explicit delimiters or specific instructions for the agent to ignore potential malicious commands embedded in the search results or tool outputs.\n
  • Capability inventory: The skill workflow utilizes multiple tools including search engines (Google Dorking), CLI tools (Holehe, Maigret), and other internal OSINT modules (person-osint, username-osint, etc.).\n
  • Sanitization: The instructions do not define methods for sanitizing, validating, or escaping content retrieved from external sources before it is analyzed or included in the final report.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 09:31 AM
Security Audit — agent-trust-hub — email-osint