osint-methodology

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze large amounts of untrusted data from external environments. This includes scraping JavaScript bundles for endpoints and secrets (§13), performing static analysis on mobile app binaries (APKs) (§14), and processing external breach logs (§22). The methodology lacks explicit instructions for the agent to use boundary markers or delimiters when handling this content, nor does it specify sanitization procedures. This creates an attack surface where malicious instructions embedded in a target's website or app could influence the agent's subsequent actions.
  • [COMMAND_EXECUTION]: The 5-stage recon pipeline and various technical modules rely on the execution of external command-line tools. These include network scanners like Nmap and Masscan, vulnerability scanners like Nuclei, and reconnaissance utilities such as Naabu, Subfinder, and Httpx (§6, §7, §9). While these are standard security tools, their use for automated network interaction is a significant capability.
  • [EXTERNAL_DOWNLOADS]: The skill describes processes for downloading external artifacts, specifically Android APKs from third-party mirror sites like APKPure (§14.3). It also involves fetching data from a wide array of external APIs and OSINT platforms (e.g., Shodan, Hunter.io, SecurityTrails, DeHashed).
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 05:31 AM
Security Audit — agent-trust-hub — osint-methodology