ctf-osint
Fail
Audited by Gen Agent Trust Hub on Apr 22, 2026
Risk Level: CRITICALREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
- [REMOTE_CODE_EXECUTION]: Automated security analysis tools flagged the presence of a malicious URL (
http://x.x.x.x:5000) inreferences/web-and-dns.md. This URL is identified as being linked to botnet operations.\n- [COMMAND_EXECUTION]: The skill instructs the agent to execute various shell commands such asdig,exiftool,curl, andgrepon user-provided data or local files to extract information.\n- [EXTERNAL_DOWNLOADS]: The skill performs numerous network operations to fetch data from external services likeip-api.com,ipinfo.io,web.archive.org, andpublic.api.bsky.appfor OSINT purposes.\n- [DATA_EXFILTRATION]: The use ofcurlto send IP addresses or other data to external geolocation and reconnaissance services constitutes a low-risk network operation, but could be abused to leak information if combined with sensitive data access.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from multiple sources which can influence agent behavior.\n - Ingestion points: Processes usernames, image files, DNS records, and social media posts (
SKILL.md,references/social-media.md).\n - Boundary markers: Lacks delimiters or instructions to treat external data as untrusted text rather than commands.\n
- Capability inventory: Extensive use of
curl,dig,exiftool, andgrepacross reference documentation.\n - Sanitization: No explicit sanitization or input validation logic is provided for the data interpolated into shell command templates.
Recommendations
- AI detected serious security threats
- Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata