Back to skill

Security audit

Threat Actor OSINT Profiling

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent OSINT threat-actor profiling aid, with disclosed external lookups and local report outputs that fit its stated purpose.

Install only if you expect your agent to perform threat-intelligence OSINT work. Treat queried actor names, indicators, and targets as potentially sensitive because they may be sent to third-party services such as MITRE GitHub content, AlienVault OTX, VirusTotal, Shodan, or SpiderFoot modules. Prefer environment variables or a secret manager over command-line API keys, and confirm legal and organizational authorization before collecting from social media, paste sites, dark web forums, or similar sources.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/agent.py:142
Finding

AlienVault OTX API Key Exposed Through Command-Line Arguments

Content
View full analysis

Vulnerability Details

File Location: scripts/agent.py, lines 142–152
Vulnerability Type: Command-line secret exposure
Risk Level: Medium
Classification: T09: Insecure Skill Coding Practices

Vulnerable Code

python
parser.add_argument("--otx-key", help="AlienVault OTX API key")
parser.add_argument("--output", default="threat_actor_profile.json")
args = parser.parse_args()

bundle = fetch_mitre_attack_data()
group_info = extract_group_info(bundle, args.group)
techniques, malware_tools = [], []
if group_info:
    techniques = extract_group_techniques(bundle, group_info["stix_id"])
    malware_tools = extract_group_malware_tools(bundle, group_info["stix_id"])
otx_results = search_alienvault_otx(args.group, args.otx_key)

Technical Analysis

The application accepts the AlienVault OTX API key through the --otx-key command-line option. Secrets passed as command-line arguments may be exposed through:

  • Shell command-history files.
  • Process inspection utilities and operating-system process interfaces.
  • Process-monitoring or diagnostic software.
  • Automation logs that record full command invocations.
  • CI/CD job definitions and build logs.

The key is subsequently placed in the documented X-OTX-API-KEY header and transmitted to AlienVault OTX over HTTPS. The reviewed code does not log the key or send it to an unauthorized endpoint. The vulnerability is therefore local secret exposure caused by the secret-input mechanism, rather than remote exfiltration by the project.

Attack Path

  1. A user invokes the agent with a command such as:
    bash
    python3 scripts/agent.py --group APT29 --otx-key SECRET_VALUE
    
  2. The full invocation may be retained in the user's shell history or exposed through process metadata while the program is running.
  3. A local user, monitoring process, compromised administrative tool, or party with access to execution logs obtains ...[truncated 894 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove or deprecate the --otx-key command-line option.
  2. Read the credential from a dedicated environment variable:
    python
    import os
    
    otx_key = os.environ.get("OTX_API_KEY")
    otx_results = search_alienvault_otx(args.group, otx_key)
    
  3. For interactive execution, optionally obtain the key through getpass.getpass() so that it is not echoed or stored in shell history:
    python
    from getpass import getpass
    
    otx_key = os.environ.get("OTX_API_KEY") or getpass("AlienVault OTX API key: ")
    
  4. For production deployments, use an operating-system credential store or managed secrets service and inject the key only at runtime.
  5. Ensure application, process-monitoring, CI/CD, and diagnostic logs do not record secret values or sensitive environment variables.
  6. Document secure credential provisioning and recommend rotating any key previously supplied on a command line.
  7. If temporary backward compatibility is required, display a security warning when --otx-key is used and prioritize safer sources over the command-line value.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The skill includes code that performs outbound network access and writes files locally, but the metadata does not declare any tool scope, permissions, or allowed-tools. This creates a transparency and governance gap: an agent or user may invoke the skill without understanding that it can transmit data to third-party services and persist artifacts to disk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill encourages collection from sensitive sources such as social media and dark web forums without warning about legal, privacy, terms-of-service, or organizational policy constraints. This omission can lead users or agents to gather data in ways that violate policy, create privacy exposure, or introduce operational risk during intelligence collection.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation guidance is overly broad and could cause the skill to be invoked in situations unrelated to threat-actor profiling. In an agent setting, vague invocation criteria increase the risk of unnecessary external lookups, over-collection from sensitive sources, and unintended processing of user or organizational data.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The code sends indicator data to Shodan, a third-party external service, which constitutes external transmission. In threat-intelligence workflows this may be legitimate, but it is still risky because queried IPs or related investigation targets may be sensitive and could disclose internal investigative interests or proprietary indicators to an outside provider.

Content

Scanner excerpt · SKILL.md (reported line 122)May include surrounding context.

md
"""Query Shodan for infrastructure details on IPs."""
        results = []
        for ip in indicators:
            url = f"https://api.shodan.io/shodan/host/{ip}?key={self.shodan_key}"
            resp = requests.get(url)
            if resp.status_code == 200:
                data = resp.json()

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The manifest description focuses on building and documenting threat actor profiles from OSINT sources. In addition to collecting and analyzing intelligence, the sample code persists a STIX bundle to disk, which is an extra behavior not stated in the short manifest description, though it is related to producing a dossier.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The manifest says the skill builds comprehensive threat actor profiles using OSINT techniques, but does not explicitly mention local file creation. The code writes a dossier markdown file, which is a concrete side effect beyond pure collection/analysis, even though it supports the stated profiling purpose.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.