osint-investigator

Warn

Audited by Socket on Mar 17, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
osint-claude/SKILL.md

SUSPICIOUS: the skill is largely aligned with its stated OSINT purpose and does not show clear credential theft or malicious exfiltration, but it grants an AI agent broad recon capability over arbitrary sites and mixes untrusted web-content ingestion with browser/fetch actions. Official tool provenance keeps supply-chain risk moderate rather than high, but the recursive investigation and prompt-injection exposure make this a medium-high security risk skill.

Confidence: 86%Severity: 66%
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is largely aligned with its stated OSINT purpose and does not show clear credential theft or malicious exfiltration, but it grants an AI agent broad recon capability over arbitrary sites and mixes untrusted web-content ingestion with browser/fetch actions. Official tool provenance keeps supply-chain risk moderate rather than high, but the recursive investigation and prompt-injection exposure make this a medium-high security risk skill.

Confidence: 86%Severity: 66%
Audit Metadata
Analyzed At
Mar 17, 2026, 08:05 AM
Package URL
pkg:socket/skills-sh/dkyazzentwatwa%2Fosint-ai%2Fosint-investigator%2F@97ed9f00d4393b5f136a930b040c5848d4baefef