offensive-osint
Operational arsenal for external red-team and bug-bounty reconnaissance. Concrete wordlists (28 Swagger paths, 13 GraphQL paths, 35 high-risk ports, 6 missing-header findings, 15 always-on HTTP checks, 5 SAML paths, cloud bucket permutations, JS guess-paths, vendor product fingerprints for Citrix/F5…
Install / Use
npx skills add elementalsouls/Claude-OSINT --skill offensive-osintInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
AutomationSupported Platforms
Our assessment of offensive-osint
offensive-osint scores 86/100 on our quality scale, 1295th of 2,257 Automation skills we index.
Its SKILL.md is 226 KB long, well organised into 400 sections with 172 code examples: long enough that it reads more like full documentation than a focused instruction file, which agents can find harder to follow.
With 2,654 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated 30 days ago, so offensive-osint is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
Safety scan
No issues foundOur scan of the first 100 KB of the file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands.
Automated pattern scan on 2026-09-29. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.
offensive-osint compared with similar skills
All 4 of these similar skills score higher than offensive-osint; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| offensive-osint (this skill)by elementalsouls | 86 | 2.7k | 30d ago | SKILL.md |
| Agent-Reachby Panniantong | 100 | 86.2k | 14d ago | CLAUDE.md |
| rufloby ruvnet | 100 | 73.5k | today | CLAUDE.md |
| Scraplingby D4Vinci | 100 | 84.5k | today | MCP Server |
| algorithmic-artby anthropics | 100 | 177.9k | 7d ago | SKILL.md |
Frequently asked questions
- How do I install offensive-osint?
- Run
npx skills add elementalsouls/Claude-OSINT --skill offensive-osint. The install tabs above show the steps for each supported agent. - Which AI agents does offensive-osint work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is offensive-osint safe to use?
- Our scan of the first 100 KB of the file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is offensive-osint still maintained?
- The repository was last updated 30 days ago, so offensive-osint is actively maintained.
Skill content
View source on GitHubname: offensive-osint description: "Operational arsenal for external red-team and bug-bounty reconnaissance. Concrete wordlists (28 Swagger paths, 13 GraphQL paths, 35 high-risk ports, 6 missing-header findings, 15 always-on HTTP checks, 5 SAML paths, cloud bucket permutations, JS guess-paths, vendor product fingerprints for Citrix/F5/Pulse/Fortinet/Cisco/PaloAlto/VMware/Exchange, cloud-native service fingerprints, container/K8s exposure paths, CI/CD platform paths, documentation/wiki leak paths, WHOIS/RDAP, DNS record catalog, Wayback CDX recipes), 80-pattern secret-regex catalog (incl. modern AI API keys: Anthropic/OpenAI/HuggingFace/Cloudflare/DigitalOcean/npm/PyPI/Docker Hub/Atlassian/DataDog/Sentry/ngrok; plus a provider-expansion tier: Postman PMAK/GitLab/Square/Shopify/Mailchimp/PagerDuty/Asana/Databricks/Grafana/Terraform Cloud/Fastly/Algolia/Segment/Airtable/GCP+Google OAuth/Azure AD/Facebook OAuth/RubyGems/JFrog/Okta/Slack app-level/Dropbox/Doppler/HashiCorp Vault/Firebase Cloud Messaging), 80+ dork corpus across 9 categories, GitHub code-search dorks, copy-paste curl/httpie probes for every check, post-discovery enumeration workflows (AWS/GitHub/Slack/JWT/PMAK/Anthropic/OpenAI), endpoint interest scoring rubric (0–100), mobile app ownership confidence + APK static-analysis pipeline (acquisition, apktool/aapt2/jadx/androguard decompile, manifest exported-component/deep-link/misconfig extraction, Firebase config, network-security-config, embedded-secret scan), identity-fabric endpoints (Entra/Okta/ADFS/Google/SAML/M365 Teams+SharePoint+OneDrive+OAuth + user-enum), GraphQL field-suggestion enumeration when introspection disabled, 9 read-only secret validators (Postman/AWS/GitHub/Slack/Anthropic/OpenAI/npm/Atlassian/DataDog), Postman workspace search (verified endpoint), Stack Exchange sweep, public SaaS dorks, email security analysis (SPF/DMARC/DKIM/BIMI/MTA-STS/DNSSEC), origin-discovery / CDN bypass techniques, TLS deep audit (sslyze/testssl.sh/JA3/JA4), reverse-DNS sweep + IPv6 enum, vulnerability prioritization data sources (NVD/EPSS/CISA KEV/ExploitDB/Metasploit), 27 attack-path hint templates, 80+ severity-matrix examples, LinkedIn employee enumeration, job posting tech-stack analysis, Slack/Discord workspace discovery, package registry leak hunting (npm/PyPI/Docker Hub/Quay/GHCR), sat imagery for physical recon, tooling quick-install one-liners, sector-specific recon notes (healthcare/finance/ICS-SCADA/IoT/government), runnable stdlib-only secret_scan.py helper, plus the existing tool references for username/email/phone/people/social/breach/infrastructure/crypto/media/geospatial/AI/archiving/automation. Use when you need concrete probe paths, regexes, payloads, scoring rules, curl one-liners, and tool URLs for an authorized external recon engagement." version: 2.2 sources: hackerone_public, community, public_research triggers:
- external recon
- external red team
- red team external
- attack surface management
- ASM
- bug bounty recon
- bug bounty
- reconnaissance
- footprinting
- asset discovery
- swagger discovery
- openapi discovery
- graphql introspection
- graphql discovery
- subdomain enumeration
- subdomain takeover
- cloud bucket enumeration
- bucket enum
- S3 enum
- GCS enum
- Azure blob enum
- identity fabric
- SSO discovery
- IdP fingerprinting
- tenant fingerprinting
- okta enum
- entra enum
- azure AD enum
- ADFS enum
- SAML metadata
- mobile recon
- APK analysis
- mobile attack surface
- secret scanning
- secret leak
- leaked credential
- github dorking
- google dorking
- bing dorking
- DDG dorking
- postman workspace
- stack exchange OSINT
- breach lookup
- have I been pwned
- HudsonRock cavalier
- infostealer
- dehashed
- intelx
- shodan recon
- censys recon
- certificate transparency
- crt.sh
- JARM
- favicon mmh3
- JS endpoint extraction
- sourcemap leak
- copy paste probes
- curl one-liner
- email security analysis
- SPF DMARC DKIM
- origin discovery
- CDN bypass
- WAF bypass
- vendor product fingerprints
- Citrix Netscaler
- F5 BIG-IP
- Pulse Secure
- FortiGate
- PaloAlto GlobalProtect
- Cisco AnyConnect
- VMware vCenter
- cloud native fingerprint
- Lambda function URL
- Cloud Run
- kubernetes exposure
- kubelet
- etcd
- CI CD exposure
- Jenkins recon
- GitLab self-hosted
- GitHub Actions secrets
- documentation leak
- Notion public
- Confluence anonymous
- Trello board
- WHOIS RDAP
- DNS record catalog
- Wayback CDX
- LinkedIn enumeration
- job posting tech stack
- Slack workspace discovery
- Discord server discovery
- npm token leak
- PyPI token leak
- Docker Hub leak
- sat imagery physical recon
- TLS deep audit
- JA3 JA4
- reverse DNS sweep
- IPv6 enumeration
- CVE prioritization
- EPSS scoring
- CISA KEV
- vulnerability prioritization
- tooling install
- sector specific recon
- healthcare DICOM
- finance SWIFT
- ICS SCADA
- Modbus
- BACnet
- post discovery workflow
- JWT triage
- AWS key triage
- GraphQL field suggestion
- Anthropic API key
- OpenAI API key
- Microsoft 365 deep
- Teams federation
- SharePoint enum
- OneDrive enum
- hackerone reference
- h1 hacktivity
- disclosed reports
- community bug reports
- prior disclosures
- bug bounty reference
Offensive OSINT — External Red-Team Arsenal
Companion skill:
osint-methodology(the "how to think" skill). This skill is the "what to reach for." Use them together.
0. When to use / When NOT
Use this skill when:
- You need concrete probe paths, wordlists, regexes, payloads, scoring rules, or tool URLs.
- You're executing reconnaissance and need the actual technical reference (vs. methodology).
- You're building a recon automation and need specific lists to seed it.
Do NOT use this skill when:
- The user is asking for active exploitation, post-exploitation, or anything past reconnaissance.
- The user is asking for defensive / blue-team detections.
- The target's authorization isn't established — see §1.
1. Authorization & Legal Posture
For assets the operator owns or has written authorization to assess. Soft scope check before acting against an unverified third-party target — see methodology skill §1 for the full posture.
2. Confidence Levels
- TENTATIVE — plausible based on indirect evidence (snippet-only dork match, single-source asset, inferred email pattern).
- FIRM — directly observed (subdomain resolves, HEAD-confirmed bucket exists, banner returned).
- CONFIRMED — verified via independent corroboration OR direct verification (live PMAK validation, multiple sources agree, listable bucket with object retrieval).
3. Output Format Conventions
Findings should carry: id, module, asset_key, category, severity (info/low/medium/high/critical), confidence, title, description, evidence (url + UTC timestamp + sha256 + raw ≤ 2 KiB), references, remediation. UTC timestamps everywhere.
4. Source Hygiene & Citations
URL + UTC timestamp + SHA-256 + tool version + run_id, every artifact. PNG screenshots, JSONL run logs, raw HTTP captures capped at 2 KiB body.
5. Do NOT
- Don't paste creds/PII/session tokens into cloud LLMs.
- Don't run destructive probes outside DEEP/
--aggressive. - Don't use validated credentials for anything except read-only liveness check.
- Don't single-source attribute.
- Don't assume vendor labels are ground truth.
6. General OSINT (curated tool refs)
- OSINT Bookmarks — comprehensive bookmarks.
- OSINT Framework — tool/resource directory.
- IntelTechniques Tools — investigative suite.
- Bellingcat Toolkit — investigative journalism.
- CyberSudo OSINT Toolkit — OSINT websites list.
- Google Dorks — efficient Google searching.
- Distributed Denial of Secrets — leaked datasets.
- Country-Specific Resources — country-targeted OSINT.
7. Search Engines
| Tool | Notes | |------|-------| | Carrot2 | Clusters results by topic | | etools | Metasearch | | Kagi | Privacy-first, non-personalized | | Brave Search | Independent index; Goggles for custom ranking | | PDF Search | PDF + table of contents | | Google Fact Check Explorer | Cross-site fact-check |
8. Username & Email Investigation
| Tool | Purpose | |------|---------| | Sherlock | Username search across social networks | | Maigret | Profile collector by username | | What's My Name | Username search | | Holehe | Email registration check | | Epieos | Email pivots and metadata | | OSINT Industries | Email/username/phone lookups | | Hunter.io | Domain → emails | | EmailRep | Email reputation | | Emailable | Email verification | | Mugetsu | X/Twitter username history | | RocketReach / Apollo | Email enrichment + pattern guessing | | PhoneInfoga | Phone number intelligence |
Browser extensions: GetProspect, SignalHire.
9. People Search
- TruePeopleSearch — free U.S. people search.
- WhitePages, Spokeo, Webmii, Pipl (paid).
- Clearbit — company/individual data enrichment.
- FaceCheck / FaceSeek — reverse face search.
10. Phone Number OSINT
- TrueCaller — caller ID + spam blocking.
- ThatsThem — reverse phone search.
- Infobel — non-USA phone search.
- FreeCarrierLookup — carrier/type (US).
- NumlookupAPI [Freemium] — programmatic carrier checks.
- CallerIDTest, Advanced Background Checks.
11. Email-Pattern Inference (TENTATIVE candidates)
Given a (first_name, last_name, domain), generate these 8 candidate addresses for breach pre-hits, phishing list curation, and downstream enrichment. Mark as TENTATIVE confidence until corroborated.
{first}.{last}@{domain} # john.doe@example.com
{first}{last}@{domain} # johndoe@example.com
{first}@{domain} # john@example.com
{first[0]}{last}@{domain} # jdoe@example.com
{first}.{last[0]}@{domain} # john.d@example.com
{last}@{domain} # doe@example.com
{first}_{last}@{domain} # john_doe@example.com
{first}-{last}@{domain} # john-doe@example.com
Lowercase before lookup. Strip diacritics for ASCII fallback. If the org uses a known pattern (e.g., Hunter.io shows {first}.{last} is dominant), prioritize that one and mark FIRM.
12.
Truncated for display — read the full file on GitHub.
Related Skills
Agent-Reach
86.2kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
ruflo
73.5k🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native Claude Code / Codex / Hermes and many more Integrated
Scrapling
84.5k🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ and follow here for daily tips and tricks: https://x.com/Scrapling_dev
algorithmic-art
177.9kCreating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
