osint-methodology
Fail
Audited by Snyk on Aug 27, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E004: Prompt injection detected in skill instructions.
- Potential prompt injection detected (critical risk: 1.00). This skill provides detailed, actionable offensive OSINT and red-team guidance (phishing infrastructure, subdomain takeover steps, WAF/CDN bypass and origin discovery, persona/sock-puppet tradecraft, detection-evasion) that can be used to commit harmful activity.
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (medium risk: 0.30). The skill explicitly directs APK acquisition via "Download via APKPure HTML scrape" (a third-party APK mirror) and includes a
go install github.com/glebarez/cero@latestcommand, both of which instruct fetching executable code from third‑party sources rather than official vetted stores/repos.
Issues (2)
E004
CRITICALPrompt injection detected in skill instructions.
E005
CRITICALSuspicious download URL detected in skill instructions.
Audit Metadata