SkillAgentSearch skills...

offensive-osint

Operational arsenal for authorized external red-team and bug-bounty recon. Concrete probes, wordlists, regexes, dorks, curl one-liners for: subdomain enum, GraphQL/Swagger/REST discovery, identity fabric (Entra/Okta/ADFS/Google/SAML/M365 deep — Teams/SharePoint/OneDrive), cloud bucket enum (S3/GCS/A…

Install / Use

npx skills add elementalsouls/Claude-BugHunter --skill offensive-osint

Installs into whichever agent you are using.

About this skill
📄

SKILL.md

Installable skill definition

Quality Score

89/100

Category

Automation

Supported Platforms

Zed

Our assessment of offensive-osint

offensive-osint scores 89/100 on our quality scale, 804th of 2,035 Automation skills we index (top 40%).

Its SKILL.md is 33 KB long, well organised into 16 sections and no code examples: a thorough specification that gives an agent plenty to work with.

With 4,669 GitHub stars, it is one of the more widely adopted skills in the catalogue.

Substance
30/30
Structure
13/20
Description
15/15
Adoption
16/20
Freshness
15/15

Maintenance, license and trust

  • The repository was last updated 2 days ago, so offensive-osint is actively maintained.
  • It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
  • Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

offensive-osint compared with similar skills

All 4 of these similar skills score higher than offensive-osint; compare them before choosing.

SkillScoreStarsUpdatedFormat
offensive-osint (this skill)by elementalsouls894.7k2d agoSKILL.md
Agent-Reachby Panniantong10085.9k13d agoCLAUDE.md
rufloby ruvnet10073.4ktodayCLAUDE.md
Scraplingby D4Vinci10084.2k1d agoMCP Server
algorithmic-artby anthropics100177.9k6d agoSKILL.md

Frequently asked questions

How do I install offensive-osint?
Run npx skills add elementalsouls/Claude-BugHunter --skill offensive-osint. The install tabs above show the steps for each supported agent.
Which AI agents does offensive-osint work with?
It is written for Zed, as a SKILL.md file. Other agents that read the same format can often use it too.
Is offensive-osint safe to use?
It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is offensive-osint still maintained?
The repository was last updated 2 days ago, so offensive-osint is actively maintained.

name: offensive-osint description: "Operational arsenal for authorized external red-team and bug-bounty recon. Concrete probes, wordlists, regexes, dorks, curl one-liners for: subdomain enum, GraphQL/Swagger/REST discovery, identity fabric (Entra/Okta/ADFS/Google/SAML/M365 deep — Teams/SharePoint/OneDrive), cloud bucket enum (S3/GCS/Azure), CDN/WAF bypass, origin discovery, vendor fingerprinting (Citrix/F5/Pulse/Fortinet/PaloAlto/Cisco/VMware), CI/CD exposure, 48-pattern secret-scan catalog (AWS/GCP/GitHub/Stripe/Slack/Anthropic/OpenAI/Atlassian/DataDog/npm/PyPI), Postman workspaces, breach correlation (HudsonRock/HIBP/DeHashed/IntelX), TLS/JA3 audit, certificate transparency, JS endpoint extraction, package registry leaks, mobile/APK recon, sat imagery, sector-specific recon (healthcare DICOM, finance SWIFT, ICS/SCADA Modbus/BACnet). Detail content in 15 modular reference files, loaded on demand. Use for any authorized recon: scoping, asset discovery, attack-path mapping, secret triage, severity scoring." sources: hackerone_public, community, public_research version: 3.0.0 triggers:

  • external recon
  • external red team
  • red team external
  • attack surface management
  • ASM
  • bug bounty recon
  • bug bounty
  • reconnaissance
  • footprinting
  • asset discovery
  • swagger discovery
  • openapi discovery
  • graphql introspection
  • graphql discovery
  • subdomain enumeration
  • subdomain takeover
  • cloud bucket enumeration
  • bucket enum
  • S3 enum
  • GCS enum
  • Azure blob enum
  • identity fabric
  • SSO discovery
  • IdP fingerprinting
  • tenant fingerprinting
  • okta enum
  • entra enum
  • azure AD enum
  • ADFS enum
  • SAML metadata
  • mobile recon
  • APK analysis
  • mobile attack surface
  • secret scanning
  • secret leak
  • leaked credential
  • github dorking
  • google dorking
  • bing dorking
  • DDG dorking
  • postman workspace
  • stack exchange OSINT
  • breach lookup
  • have I been pwned
  • HudsonRock cavalier
  • infostealer
  • dehashed
  • intelx
  • shodan recon
  • censys recon
  • certificate transparency
  • crt.sh
  • JARM
  • favicon mmh3
  • JS endpoint extraction
  • sourcemap leak
  • copy paste probes
  • curl one-liner
  • email security analysis
  • SPF DMARC DKIM
  • origin discovery
  • CDN bypass
  • WAF bypass
  • vendor product fingerprints
  • Citrix Netscaler
  • F5 BIG-IP
  • Pulse Secure
  • FortiGate
  • PaloAlto GlobalProtect
  • Cisco AnyConnect
  • VMware vCenter
  • cloud native fingerprint
  • Lambda function URL
  • Cloud Run
  • kubernetes exposure
  • kubelet
  • etcd
  • CI CD exposure
  • Jenkins recon
  • GitLab self-hosted
  • GitHub Actions secrets
  • documentation leak
  • Notion public
  • Confluence anonymous
  • Trello board
  • WHOIS RDAP
  • DNS record catalog
  • Wayback CDX
  • LinkedIn enumeration
  • job posting tech stack
  • Slack workspace discovery
  • Discord server discovery
  • npm token leak
  • PyPI token leak
  • Docker Hub leak
  • sat imagery physical recon
  • TLS deep audit
  • JA3 JA4
  • reverse DNS sweep
  • IPv6 enumeration
  • CVE prioritization
  • EPSS scoring
  • CISA KEV
  • vulnerability prioritization
  • tooling install
  • sector specific recon
  • healthcare DICOM
  • finance SWIFT
  • ICS SCADA
  • Modbus
  • BACnet
  • post discovery workflow
  • JWT triage
  • AWS key triage
  • GraphQL field suggestion
  • Anthropic API key
  • OpenAI API key
  • Microsoft 365 deep
  • Teams federation
  • SharePoint enum
  • OneDrive enum
  • hackerone reference
  • h1 hacktivity
  • disclosed reports
  • community bug reports
  • prior disclosures
  • bug bounty reference

Offensive OSINT — External Red-Team Arsenal

v3.0 — Refactored 2026-05-02 from a 4,168-line monolith into a lean SKILL.md (~400 lines) plus 15 modular reference files in references/. Detail content loads on demand — Claude reads only the reference files relevant to the current task.

0. When to use / When NOT

Use this skill when:

  • You need concrete probe paths, wordlists, regexes, payloads, scoring rules, or tool URLs.
  • You're executing reconnaissance and need the actual technical reference (vs. methodology).
  • You're building a recon automation and need specific lists to seed it.

Do NOT use this skill when:

  • The user is asking for active exploitation, post-exploitation, or anything past reconnaissance.
  • The user is asking for defensive / blue-team detections.
  • The target's authorization isn't established — see §1.

1. Authorization & Legal Posture

For assets the operator owns or has written authorization to assess. Soft scope check before acting against an unverified third-party target — see methodology skill §1 for the full posture.


2. Confidence Levels

  • TENTATIVE — plausible based on indirect evidence (snippet-only dork match, single-source asset, inferred email pattern).
  • FIRM — directly observed (subdomain resolves, HEAD-confirmed bucket exists, banner returned).
  • CONFIRMED — verified via independent corroboration OR direct verification (live PMAK validation, multiple sources agree, listable bucket with object retrieval).

3. Output Format Conventions

Findings should carry: id, module, asset_key, category, severity (info/low/medium/high/critical), confidence, title, description, evidence (url + UTC timestamp + sha256 + raw ≤ 2 KiB), references, remediation. UTC timestamps everywhere.


4. Source Hygiene & Citations

URL + UTC timestamp + SHA-256 + tool version + run_id, every artifact. PNG screenshots, JSONL run logs, raw HTTP captures capped at 2 KiB body.


5. Do NOT

  • Don't paste creds/PII/session tokens into cloud LLMs.
  • Don't run destructive probes outside DEEP/--aggressive.
  • Don't use validated credentials for anything except read-only liveness check.
  • Don't single-source attribute.
  • Don't assume vendor labels are ground truth.

6. General OSINT (curated tool refs)


How to use this skill

This skill is a lean operational index. Most concrete data (wordlists, regexes, dorks, endpoint catalogs, severity examples) lives in the references/ subfolder, organized by topic.

Workflow when this skill triggers:

  1. Read this SKILL.md to anchor on principles (§0-5), scoring rubrics (§20-21), attack-path templates (§39), and the references index below.
  2. For task-specific data, read only the reference file(s) you need — do NOT pull all 15. Each reference is self-contained.
  3. Use the bug-bounty skill for the local toolkit at ~/security-research/bug-bounty-resources/ and osint-methodology for the planning framework.

Loading rules of thumb:

  • Single-class question (e.g., "what's the regex for AWS keys?") → load secret-patterns.md only.
  • Multi-class engagement (e.g., "do an external recon on target.com") → load probes-and-wordlists.md first, then add others as the engagement narrows.
  • Severity / triage question → load severity-matrix.md.

References Index

| File | Coverage | Trigger phrases | |---|---|---| | probes-and-wordlists.md | API/Swagger/GraphQL paths, cloud-bucket arsenal, JS guess-paths, vendor & cloud-native fingerprints, K8s/CI-CD exposure, doc/wiki leaks, WHOIS/RDAP, DNS catalog, Wayback CDX, copy-paste curl probes, email security analysis, origin/CDN bypass | swagger discovery, graphql introspection, subdomain takeover, cloud bucket enum, S3/GCS/Azure enum, kubernetes exposure, CI CD exposure, vendor fingerprint, WHOIS RDAP, Wayback CDX, copy paste probes, curl one-liner | | identity-fabric.md | Concrete endpoints for Entra/Okta/ADFS/Google/SAML, M365 deep (Teams federation, SharePoint, OneDrive), GraphQL field-suggestion enumeration, user-enum patterns | identity fabric, SSO discovery, IdP fingerprinting, okta enum, entra enum, azure AD enum, ADFS enum, SAML metadata, Microsoft 365 deep, Teams federation, SharePoint enum, OneDrive enum, graphql field suggestion | | secret-patterns.md | 48-pattern secret-regex catalog (AWS, GCP, GitHub PATs, Stripe, Slack, JWT, private keys, Anthropic/OpenAI/HuggingFace, Cloudflare, DigitalOcean, npm, PyPI, Docker Hub, Atlassian, DataDog, Sentry, ngrok) with severity & FP notes | secret scanning, secret leak, leaked credential, JWT triage, AWS key triage, Anthropic API key, OpenAI API key | | secret-validators.md | 9 read-only secret validators + post-discovery enumeration workflows for AWS/GitHub/Slack/Postman/JWT/Anthropic/OpenAI/npm/Atlassian/DataDog | secret validation, post discovery workflow, AWS key triage, JWT triage | | dork-corpus.md | 80+ Google/Bing/DDG dork templates across 9 categories + 13 GitHub code-search dorks tailored for targets | google dorking, bing dorking, github dorking, dork corpus | | recon-stack.md | Subdomain-source stack (passive & active), infrastructure & attack-surface OSINT (Shodan/Censys/crt.sh/JARM/favicon mmh3), TLS deep audit, reverse DNS, IPv6 enumeration | subdomain enumeration, certificate transparency, crt.sh, shodan recon, censys recon, JARM, favicon mmh3, TLS deep audit, JA3 JA4, reverse DNS sweep, IPv6 enumeration | | breach-and-credentials.md | Breach & leak data sources (HudsonRock, HIBP, DeHashed, IntelX, infostealer logs), email-pattern inference, email-harvest source stack | breach lookup, have I been pwned, HudsonRock cavalier, infostealer, dehashed, intelx, email harvest | | people-osint.md | Search engines, username & email investigation, people search, phone OSINT, social media, public records & company info | username investigation, people search, phone OSINT, social media OSINT, public records | | saas-public-surfaces.md | Postman public workspace search (verified endpoint), Stack Exchange OSINT sweep, public SaaS dork stack (Notion, Confluence, Trello) | postman workspace, stack exchange OSINT, Notion public, Confluence anonymous, Trello board | | specialized-osint.md | Threat intel & IOCs, cryptocurrency OSINT, media intelligence, geospatial intelligence, regional search engines, Telegram & messaging intelligence | threat intel, IOCs, cryptocurrency OSINT, media intelligence, geospatial OSINT, regional search, Telegram intelligence | | recon-techniques.md | LinkedIn employee enumeration, job-posting tech-stack analysis, Slack/Discord/Telegram workspace discovery, package-registry leak hunting (npm/PyPI/Docker Hub/Quay/GHCR), sat imagery for physical recon | LinkedIn enumeration, job posting tech stack, Slack workspace discovery, Discord server discovery, npm token leak, PyPI token leak, Docker Hub leak, sat imagery physical recon | | severity-matrix.md | 80+ worked examples mapping observed conditions → finding severity (CRITICAL/HIGH/MEDIUM/LOW/INFO) | severity decision, finding severity, severity matrix | | sector-notes.md | Recon notes for healthcare (DICOM), finance (SWIFT), ICS/SCADA (Modbus/BACnet), IoT, government | sector specific recon, healthcare DICOM, finance SWIFT, ICS SCADA, Modbus, BACnet | | tooling-install.md | Quick-install one-liners for Subfinder, Amass, httpx, nuclei, gau, katana, gowitness, dnsx, mapcidr, naabu, sslyze, testssl.sh, etc. | tooling install, install subfinder, install nuclei, install httpx | | `helpers-and-auto

Truncated for display — read the full file on GitHub.

Related Skills

View on GitHub
GitHub Stars4.7k
CategoryAutomation
Updated2d ago
Forks704

Languages

Python

Trust signals

100/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

No cautions