osint-methodology

Fail

Audited by Snyk on Aug 27, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E004: Prompt injection detected in skill instructions.

  • Potential prompt injection detected (critical risk: 1.00). This skill provides detailed, actionable offensive OSINT and red-team guidance (phishing infrastructure, subdomain takeover steps, WAF/CDN bypass and origin discovery, persona/sock-puppet tradecraft, detection-evasion) that can be used to commit harmful activity.

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (medium risk: 0.30). The skill explicitly directs APK acquisition via "Download via APKPure HTML scrape" (a third-party APK mirror) and includes a go install github.com/glebarez/cero@latest command, both of which instruct fetching executable code from third‑party sources rather than official vetted stores/repos.

Issues (2)

E004
CRITICAL

Prompt injection detected in skill instructions.

E005
CRITICAL

Suspicious download URL detected in skill instructions.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 27, 2026, 05:32 AM
Issues
2
Security Audit — snyk — osint-methodology