find-anyone
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from a wide variety of untrusted external sources, including social media platforms, web archives, and public forums, which can contain adversarial content.
- Ingestion points: Data enters the agent context through tools like
hunt-a-handle,google-like-a-spy,read-deleted-pages, anddig-through-data-brokerswhich fetch content from the public web and social media profiles (SKILL.md, Step 3). - Boundary markers: The instructions lack specific boundary markers or system instructions to treat data from these external tools as untrusted or to ignore instructions embedded within them.
- Capability inventory: The skill possesses capabilities to aggregate data, synthesize it into reports, and pivot to further network-based lookups based on found selectors (SKILL.md, Pivots table).
- Sanitization: No evidence of sanitization, filtering, or validation of the content retrieved from external sources before it is processed by the agent.
- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill facilitates the systematic collection of personally identifiable information (PII) including home addresses, family structures, asset ownership, and employment history.
- Evidence: The workflow explicitly directs the agent to gather data from property registries, voter files, and obituaries to build a detailed dossier on a subject (reference/source-catalogue.md). While intended for OSINT, this represents a significant data collection capability.
Audit Metadata