Навыки what-leaked-about-you
📦

what-leaked-about-you

Ревизия содержимого r1 Высокий риск ⚙️ Внешние команды📁 Доступ к файловой системе🔑 Переменные окружения

Assess Your Data Breach Exposure

Breach results are difficult to verify, interpret, and handle without exposing sensitive data. This skill provides a structured workflow for authorized analysis and reporting.

Поддерживает: Claude Codex Code(CC)
⚠️ 38 Плохо

Установить с помощью моего Агента

Скопируйте этот запрос в своего Агента. Он содержит каноническую страницу Skill и манифест.

Запрос агента
Review the Skillstore skill "what-leaked-about-you" from https://skillstore.io/skills/useosint-what-leaked-about-you.md and its manifest at https://skillstore.io/api/skills/useosint-what-leaked-about-you/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.

Ваш Агент по-прежнему должен показать план и запросить все подтверждения, требуемые политикой безопасности.

Ресурсы для AI-агентов

Используйте эти ссылки, когда AI-агенту, crawler или script нужен чистый контекст вместо полной страницы.

Протестировать

Использование «what-leaked-about-you». HIBP reports a verified forum breach containing email addresses, usernames, IP addresses, and password hashes.

Ожидаемый результат:

Confirmed exposure to the named forum. Change any reused password, enable multifactor authentication, review the recovered username, and never attempt login with leaked credentials.

Использование «what-leaked-about-you». A commercial corpus shows one unattributed email and password pair with no source date.

Ожидаемый результат:

Unconfirmed exposure. Record the vendor and retrieval date, exclude the credential value, and do not attribute the record to any service.

Использование «what-leaked-about-you». A client asks whether an existing password appears in known breach data.

Ожидаемый результат:

Use the Pwned Passwords range method locally. Send only the five-character SHA-1 prefix, compare suffixes locally, and do not log the password.

Аудит безопасности

Высокий риск

All 25 static findings are false positives caused by Markdown links, inline code, and explanatory security terminology. No executable command, environment access, path traversal, or cryptographic implementation appears in the reviewed files. However, the skill encourages sensitive breach-record retrieval and pre-employment screening, creating substantial privacy and misuse risks.

3
Просканировано файлов
459
Проанализировано строк
0
Пункты проверки
0
Ложные срабатывания проигнорированы

Подтверждённые проблемы безопасности (2)

Высокий
Sensitive Breach-Record Retrieval and Identity Profiling
The skill recommends services that return leaked field values, then uses those records to map identities and memberships across services.
The instructions explicitly describe retrieving record-level values and using usernames, phones, IP addresses, names, and passwords as cross-service identity signals.
Высокий
Employment Screening With Breached Personal Data
The declared scope includes pre-employment screening, although source licenses may prohibit employment decisions and breach records contain sensitive personal data.
The front matter names pre-employment screening, while the source guidance explicitly warns that licenses may prohibit employment use.

Факторы риска

Аудитор:: codex
Поделиться и цитировать этот отчет

Делитесь версионным отчетом об оценке, нейтральным значком, встраиваемой карточкой и цитатами. Skillstore публикует доказательства, не решая, безопасен ли этот Skill.

Открыть версионный отчет
Оценка безопасности

Копировать ссылку на отчёт

https://skillstore.io/skills/useosint-what-leaked-about-you/audits/1?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Значок Markdown

[![Skillstore security assessment](https://skillstore.io/badges/skills/useosint-what-leaked-about-you/security.svg)](https://skillstore.io/skills/useosint-what-leaked-about-you?utm_source=security_passport_badge)

Значок HTML

<a href="https://skillstore.io/skills/useosint-what-leaked-about-you?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/useosint-what-leaked-about-you/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Встраиваемая карточка

<iframe src="https://skillstore.io/embed/skills/useosint-what-leaked-about-you.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Академические ссылки (APA · BibTeX · CFF)

Цитата APA

useosint. (2026). what-leaked-about-you security audit report (audit version 1) [Author version unspecified]. Skillstore. https://skillstore.io/skills/useosint-what-leaked-about-you/audits/1

Цитата BibTeX

@techreport{useosint-useosint-what-leaked-about-you-2026, author = {useosint}, title = {what-leaked-about-you security audit report (audit version 1)}, institution = {Skillstore}, year = {2026}, number = {1}, url = {https://skillstore.io/skills/useosint-what-leaked-about-you/audits/1}, note = {Author version unspecified} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "what-leaked-about-you security audit report (audit version 1)" version: "unspecified" type: report authors: - name: "useosint" date-released: "2026-08-03" url: "https://skillstore.io/skills/useosint-what-leaked-about-you/audits/1" identifiers: - type: other value: "skillstore:useosint-what-leaked-about-you:audit:1" description: "Skillstore immutable audit report identifier"

Оценка Skillstore

Почему такая оценка Достоверность доказательств: Средний
55
Архитектура
85
Сопровождаемость
87
Контент
65
Сообщество
83
Соответствие спецификации

Что вы можете построить

Review Personal Exposure

Plan a self-audit that identifies exposed services, minimizes retained data, and prioritizes password changes without testing leaked credentials.

Triage an Account Compromise

Interpret authorized breach results, assess source confidence, and prepare remediation steps during an incident response investigation.

Protect an Authorized Client

Evaluate a client's exposure under written authority, document provenance, and report only findings relevant to the agreed objective.

Попробуйте эти промпты

Plan a Personal Breach Check
Create a privacy-preserving plan to check my own email address for breach exposure. Do not request or reproduce any password.
Interpret a Breach Summary
Interpret this authorized breach summary: [summary]. Separate confirmed facts, uncertain claims, affected data classes, and recommended account actions.
Assess Record Credibility
Assess these authorized records: [record descriptions]. Compare attribution, field structure, dates, provenance, duplication, and independent corroboration without retaining credential values.
Design a Controlled Investigation
Design an authorized breach-exposure investigation for [objective]. Define lawful scope, allowed selectors, source order, confidence rules, retention limits, and reporting boundaries.

Лучшие практики

  • Obtain explicit authority and define the investigative objective before querying any identifier.
  • Start with curated membership-only sources and retrieve record-level fields only when necessary.
  • Exclude credentials, minimize personal data, encrypt evidence, log access, and delete records on schedule.

Избегать

  • Never authenticate, reset an account, or test password reuse with leaked credentials.
  • Do not treat combolists, duplicate vendor results, or public scrapes as independently verified breaches.
  • Do not expand identity pivots beyond the documented scope or use breach data for employment decisions.

Часто задаваемые вопросы

Does this skill search breach databases automatically?
No. It provides source-selection, interpretation, confidence, handling, and reporting guidance.
Can I check another person's email address?
Only with a valid lawful basis and appropriate authority. Self-audits and documented client investigations provide the clearest scope.
Does a missing result prove that no breach occurred?
No. A breach may be unpublished, unindexed, restricted, or absent from the selected source.
Can I test a leaked password on an account?
No. Never authenticate, request a reset, or test reuse with leaked credentials.
How should I check a password I already control?
Use the Pwned Passwords range method locally, avoid logs, and discard the plaintext immediately.
How should uncertain records be reported?
State the source, retrieval date, attribution limits, corroboration status, and confidence grade. Do not present uncertain records as confirmed facts.

Сведения для разработчиков

Автор

useosint

Лицензия

MIT

Ревизия Skillstore

r1

Примечание о версии

Автор не указал версию.

Ссылка

76c3621ba67d9236f7e0674bbf2a2ecc2696e20c

Актуальность поддержки

03.08.2026

Использование

0 загрузок · 0 просмотров

Структура файлов