skills/wgpsec/aboutsecurity/ctf-osint/Gen Agent Trust Hub

ctf-osint

Fail

Audited by Gen Agent Trust Hub on Apr 22, 2026

Risk Level: CRITICALREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: Automated security analysis tools flagged the presence of a malicious URL (http://x.x.x.x:5000) in references/web-and-dns.md. This URL is identified as being linked to botnet operations.\n- [COMMAND_EXECUTION]: The skill instructs the agent to execute various shell commands such as dig, exiftool, curl, and grep on user-provided data or local files to extract information.\n- [EXTERNAL_DOWNLOADS]: The skill performs numerous network operations to fetch data from external services like ip-api.com, ipinfo.io, web.archive.org, and public.api.bsky.app for OSINT purposes.\n- [DATA_EXFILTRATION]: The use of curl to send IP addresses or other data to external geolocation and reconnaissance services constitutes a low-risk network operation, but could be abused to leak information if combined with sensitive data access.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from multiple sources which can influence agent behavior.\n
  • Ingestion points: Processes usernames, image files, DNS records, and social media posts (SKILL.md, references/social-media.md).\n
  • Boundary markers: Lacks delimiters or instructions to treat external data as untrusted text rather than commands.\n
  • Capability inventory: Extensive use of curl, dig, exiftool, and grep across reference documentation.\n
  • Sanitization: No explicit sanitization or input validation logic is provided for the data interpolated into shell command templates.
Recommendations
  • AI detected serious security threats
  • Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Apr 22, 2026, 07:58 AM
Security Audit — agent-trust-hub — ctf-osint