SkillAgentSearch skills...

offensive-osint

Operational arsenal for external red-team and bug-bounty reconnaissance. Concrete wordlists (28 Swagger paths, 13 GraphQL paths, 35 high-risk ports, 6 missing-header findings, 15 always-on HTTP checks, 5 SAML paths, cloud bucket permutations, JS guess-paths, vendor product fingerprints for Citrix/F5…

Install / Use

npx skills add elementalsouls/Claude-OSINT --skill offensive-osint

Installs into whichever agent you are using.

About this skill
📄

SKILL.md

Installable skill definition

Quality Score

86/100

Category

Automation

Supported Platforms

Universal

Our assessment of offensive-osint

offensive-osint scores 86/100 on our quality scale, 1295th of 2,257 Automation skills we index.

Its SKILL.md is 226 KB long, well organised into 400 sections with 172 code examples: long enough that it reads more like full documentation than a focused instruction file, which agents can find harder to follow.

With 2,654 GitHub stars, it is one of the more widely adopted skills in the catalogue.

Substance
21/30
Structure
20/20
Description
15/15
Adoption
15/20
Freshness
15/15

Maintenance, license and trust

  • The repository was last updated 30 days ago, so offensive-osint is actively maintained.
  • It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
  • Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

Safety scan

No issues found

Our scan of the first 100 KB of the file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands.

Automated pattern scan on 2026-09-29. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.

offensive-osint compared with similar skills

All 4 of these similar skills score higher than offensive-osint; compare them before choosing.

SkillScoreStarsUpdatedFormat
offensive-osint (this skill)by elementalsouls862.7k30d agoSKILL.md
Agent-Reachby Panniantong10086.2k14d agoCLAUDE.md
rufloby ruvnet10073.5ktodayCLAUDE.md
Scraplingby D4Vinci10084.5ktodayMCP Server
algorithmic-artby anthropics100177.9k7d agoSKILL.md

Frequently asked questions

How do I install offensive-osint?
Run npx skills add elementalsouls/Claude-OSINT --skill offensive-osint. The install tabs above show the steps for each supported agent.
Which AI agents does offensive-osint work with?
It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
Is offensive-osint safe to use?
Our scan of the first 100 KB of the file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is offensive-osint still maintained?
The repository was last updated 30 days ago, so offensive-osint is actively maintained.

name: offensive-osint description: "Operational arsenal for external red-team and bug-bounty reconnaissance. Concrete wordlists (28 Swagger paths, 13 GraphQL paths, 35 high-risk ports, 6 missing-header findings, 15 always-on HTTP checks, 5 SAML paths, cloud bucket permutations, JS guess-paths, vendor product fingerprints for Citrix/F5/Pulse/Fortinet/Cisco/PaloAlto/VMware/Exchange, cloud-native service fingerprints, container/K8s exposure paths, CI/CD platform paths, documentation/wiki leak paths, WHOIS/RDAP, DNS record catalog, Wayback CDX recipes), 80-pattern secret-regex catalog (incl. modern AI API keys: Anthropic/OpenAI/HuggingFace/Cloudflare/DigitalOcean/npm/PyPI/Docker Hub/Atlassian/DataDog/Sentry/ngrok; plus a provider-expansion tier: Postman PMAK/GitLab/Square/Shopify/Mailchimp/PagerDuty/Asana/Databricks/Grafana/Terraform Cloud/Fastly/Algolia/Segment/Airtable/GCP+Google OAuth/Azure AD/Facebook OAuth/RubyGems/JFrog/Okta/Slack app-level/Dropbox/Doppler/HashiCorp Vault/Firebase Cloud Messaging), 80+ dork corpus across 9 categories, GitHub code-search dorks, copy-paste curl/httpie probes for every check, post-discovery enumeration workflows (AWS/GitHub/Slack/JWT/PMAK/Anthropic/OpenAI), endpoint interest scoring rubric (0–100), mobile app ownership confidence + APK static-analysis pipeline (acquisition, apktool/aapt2/jadx/androguard decompile, manifest exported-component/deep-link/misconfig extraction, Firebase config, network-security-config, embedded-secret scan), identity-fabric endpoints (Entra/Okta/ADFS/Google/SAML/M365 Teams+SharePoint+OneDrive+OAuth + user-enum), GraphQL field-suggestion enumeration when introspection disabled, 9 read-only secret validators (Postman/AWS/GitHub/Slack/Anthropic/OpenAI/npm/Atlassian/DataDog), Postman workspace search (verified endpoint), Stack Exchange sweep, public SaaS dorks, email security analysis (SPF/DMARC/DKIM/BIMI/MTA-STS/DNSSEC), origin-discovery / CDN bypass techniques, TLS deep audit (sslyze/testssl.sh/JA3/JA4), reverse-DNS sweep + IPv6 enum, vulnerability prioritization data sources (NVD/EPSS/CISA KEV/ExploitDB/Metasploit), 27 attack-path hint templates, 80+ severity-matrix examples, LinkedIn employee enumeration, job posting tech-stack analysis, Slack/Discord workspace discovery, package registry leak hunting (npm/PyPI/Docker Hub/Quay/GHCR), sat imagery for physical recon, tooling quick-install one-liners, sector-specific recon notes (healthcare/finance/ICS-SCADA/IoT/government), runnable stdlib-only secret_scan.py helper, plus the existing tool references for username/email/phone/people/social/breach/infrastructure/crypto/media/geospatial/AI/archiving/automation. Use when you need concrete probe paths, regexes, payloads, scoring rules, curl one-liners, and tool URLs for an authorized external recon engagement." version: 2.2 sources: hackerone_public, community, public_research triggers:

  • external recon
  • external red team
  • red team external
  • attack surface management
  • ASM
  • bug bounty recon
  • bug bounty
  • reconnaissance
  • footprinting
  • asset discovery
  • swagger discovery
  • openapi discovery
  • graphql introspection
  • graphql discovery
  • subdomain enumeration
  • subdomain takeover
  • cloud bucket enumeration
  • bucket enum
  • S3 enum
  • GCS enum
  • Azure blob enum
  • identity fabric
  • SSO discovery
  • IdP fingerprinting
  • tenant fingerprinting
  • okta enum
  • entra enum
  • azure AD enum
  • ADFS enum
  • SAML metadata
  • mobile recon
  • APK analysis
  • mobile attack surface
  • secret scanning
  • secret leak
  • leaked credential
  • github dorking
  • google dorking
  • bing dorking
  • DDG dorking
  • postman workspace
  • stack exchange OSINT
  • breach lookup
  • have I been pwned
  • HudsonRock cavalier
  • infostealer
  • dehashed
  • intelx
  • shodan recon
  • censys recon
  • certificate transparency
  • crt.sh
  • JARM
  • favicon mmh3
  • JS endpoint extraction
  • sourcemap leak
  • copy paste probes
  • curl one-liner
  • email security analysis
  • SPF DMARC DKIM
  • origin discovery
  • CDN bypass
  • WAF bypass
  • vendor product fingerprints
  • Citrix Netscaler
  • F5 BIG-IP
  • Pulse Secure
  • FortiGate
  • PaloAlto GlobalProtect
  • Cisco AnyConnect
  • VMware vCenter
  • cloud native fingerprint
  • Lambda function URL
  • Cloud Run
  • kubernetes exposure
  • kubelet
  • etcd
  • CI CD exposure
  • Jenkins recon
  • GitLab self-hosted
  • GitHub Actions secrets
  • documentation leak
  • Notion public
  • Confluence anonymous
  • Trello board
  • WHOIS RDAP
  • DNS record catalog
  • Wayback CDX
  • LinkedIn enumeration
  • job posting tech stack
  • Slack workspace discovery
  • Discord server discovery
  • npm token leak
  • PyPI token leak
  • Docker Hub leak
  • sat imagery physical recon
  • TLS deep audit
  • JA3 JA4
  • reverse DNS sweep
  • IPv6 enumeration
  • CVE prioritization
  • EPSS scoring
  • CISA KEV
  • vulnerability prioritization
  • tooling install
  • sector specific recon
  • healthcare DICOM
  • finance SWIFT
  • ICS SCADA
  • Modbus
  • BACnet
  • post discovery workflow
  • JWT triage
  • AWS key triage
  • GraphQL field suggestion
  • Anthropic API key
  • OpenAI API key
  • Microsoft 365 deep
  • Teams federation
  • SharePoint enum
  • OneDrive enum
  • hackerone reference
  • h1 hacktivity
  • disclosed reports
  • community bug reports
  • prior disclosures
  • bug bounty reference

Offensive OSINT — External Red-Team Arsenal

Companion skill: osint-methodology (the "how to think" skill). This skill is the "what to reach for." Use them together.

0. When to use / When NOT

Use this skill when:

  • You need concrete probe paths, wordlists, regexes, payloads, scoring rules, or tool URLs.
  • You're executing reconnaissance and need the actual technical reference (vs. methodology).
  • You're building a recon automation and need specific lists to seed it.

Do NOT use this skill when:

  • The user is asking for active exploitation, post-exploitation, or anything past reconnaissance.
  • The user is asking for defensive / blue-team detections.
  • The target's authorization isn't established — see §1.

1. Authorization & Legal Posture

For assets the operator owns or has written authorization to assess. Soft scope check before acting against an unverified third-party target — see methodology skill §1 for the full posture.


2. Confidence Levels

  • TENTATIVE — plausible based on indirect evidence (snippet-only dork match, single-source asset, inferred email pattern).
  • FIRM — directly observed (subdomain resolves, HEAD-confirmed bucket exists, banner returned).
  • CONFIRMED — verified via independent corroboration OR direct verification (live PMAK validation, multiple sources agree, listable bucket with object retrieval).

3. Output Format Conventions

Findings should carry: id, module, asset_key, category, severity (info/low/medium/high/critical), confidence, title, description, evidence (url + UTC timestamp + sha256 + raw ≤ 2 KiB), references, remediation. UTC timestamps everywhere.


4. Source Hygiene & Citations

URL + UTC timestamp + SHA-256 + tool version + run_id, every artifact. PNG screenshots, JSONL run logs, raw HTTP captures capped at 2 KiB body.


5. Do NOT

  • Don't paste creds/PII/session tokens into cloud LLMs.
  • Don't run destructive probes outside DEEP/--aggressive.
  • Don't use validated credentials for anything except read-only liveness check.
  • Don't single-source attribute.
  • Don't assume vendor labels are ground truth.

6. General OSINT (curated tool refs)

7. Search Engines

| Tool | Notes | |------|-------| | Carrot2 | Clusters results by topic | | etools | Metasearch | | Kagi | Privacy-first, non-personalized | | Brave Search | Independent index; Goggles for custom ranking | | PDF Search | PDF + table of contents | | Google Fact Check Explorer | Cross-site fact-check |


8. Username & Email Investigation

| Tool | Purpose | |------|---------| | Sherlock | Username search across social networks | | Maigret | Profile collector by username | | What's My Name | Username search | | Holehe | Email registration check | | Epieos | Email pivots and metadata | | OSINT Industries | Email/username/phone lookups | | Hunter.io | Domain → emails | | EmailRep | Email reputation | | Emailable | Email verification | | Mugetsu | X/Twitter username history | | RocketReach / Apollo | Email enrichment + pattern guessing | | PhoneInfoga | Phone number intelligence |

Browser extensions: GetProspect, SignalHire.


9. People Search


10. Phone Number OSINT


11. Email-Pattern Inference (TENTATIVE candidates)

Given a (first_name, last_name, domain), generate these 8 candidate addresses for breach pre-hits, phishing list curation, and downstream enrichment. Mark as TENTATIVE confidence until corroborated.

{first}.{last}@{domain}        # john.doe@example.com
{first}{last}@{domain}         # johndoe@example.com
{first}@{domain}               # john@example.com
{first[0]}{last}@{domain}      # jdoe@example.com
{first}.{last[0]}@{domain}     # john.d@example.com
{last}@{domain}                # doe@example.com
{first}_{last}@{domain}        # john_doe@example.com
{first}-{last}@{domain}        # john-doe@example.com

Lowercase before lookup. Strip diacritics for ASCII fallback. If the org uses a known pattern (e.g., Hunter.io shows {first}.{last} is dominant), prioritize that one and mark FIRM.


12.

Truncated for display — read the full file on GitHub.

Related Skills

View on GitHub
GitHub Stars2.7k
CategoryAutomation
Updated1mo ago
Forks478

Languages

Python

Trust signals

100/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

No cautions