who-really-owns-it
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists entirely of instructional Markdown content providing workflows for corporate intelligence and does not contain any executable scripts, command line tools, or remote code downloads.
- [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow for ingesting and analyzing data from external, untrusted corporate registries.
- Ingestion points: Data retrieved from third-party sources such as OpenCorporates, Companies House, SEC EDGAR, and various national business registers.
- Boundary markers: The instructions do not define specific delimiters or guidelines to prevent the agent from following instructions potentially embedded in external registry data.
- Capability inventory: While the skill itself has no code, it directs the agent to utilize other OSINT tools (e.g., find-anyone, graph-the-network) to process retrieved information.
- Sanitization: No explicit mention is made of sanitizing or validating external registry content before analysis.
- Assessment: This represents a standard operational surface for OSINT research tools and is considered safe within the context of its primary purpose.
Audit Metadata