person-osint

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill contains high-level instructional content for conducting investigations into public data. It functions as a procedural guide rather than executing scripts or commands directly. No patterns for credential theft, exfiltration, or unauthorized persistence were identified.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process information from external, untrusted sources such as social media profiles, search results, and image metadata. This creates a surface for indirect prompt injection if the external data contains instructions intended to manipulate the agent's behavior.
  • Ingestion points: Data gathered in Step 3 from public web searches, social media handles, and file metadata.
  • Boundary markers: The instructions do not define specific delimiters or warnings for the agent to ignore instructions embedded in the retrieved data.
  • Capability inventory: The workflow directs the agent to utilize a variety of specialized OSINT tools (e.g., google-dorking, username-osint, reverse-image-search).
  • Sanitization: The skill does not prescribe specific sanitization or validation logic for the external data before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 09:30 AM
Security Audit — agent-trust-hub — person-osint