Back to skill

Security audit

Threat Actor OSINT Profiling

Security checks across malware telemetry and agentic risk

Overview

The skill appears to perform expected threat-intelligence lookups, but users should know that queried actors, IOCs, or targets may be sent to external OSINT providers.

Before installing, confirm you are comfortable sending searched actor names, domains, IPs, hashes, or other IOCs to the referenced third-party OSINT services. Avoid using it on sensitive investigations unless you have approval or an offline/private workflow.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The examples call third-party OSINT APIs using actor names and indicators without explicitly warning that user-supplied data will be transmitted externally. In threat-intelligence workflows, targets, IOCs, or investigation context may themselves be sensitive, so silent disclosure can leak investigative intent or proprietary data.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.