osint-investigator
Audited by Socket on Mar 17, 2026
2 alerts found:
Anomalyx2SUSPICIOUS: the skill is largely aligned with its stated OSINT purpose and does not show clear credential theft or malicious exfiltration, but it grants an AI agent broad recon capability over arbitrary sites and mixes untrusted web-content ingestion with browser/fetch actions. Official tool provenance keeps supply-chain risk moderate rather than high, but the recursive investigation and prompt-injection exposure make this a medium-high security risk skill.
SUSPICIOUS: the skill is largely aligned with its stated OSINT purpose and does not show clear credential theft or malicious exfiltration, but it grants an AI agent broad recon capability over arbitrary sites and mixes untrusted web-content ingestion with browser/fetch actions. Official tool provenance keeps supply-chain risk moderate rather than high, but the recursive investigation and prompt-injection exposure make this a medium-high security risk skill.