osint-autopilot
End-to-end external OSINT engagement autopilot. Run the FULL osint-methodology pipeline to completion in ONE go for an authorized domain — engagement folder, Stages 1-5 (seed, expansion, enrichment, exposure, convergence), multi-agent per-host content+JS fan-out, headline verification, auto-generate…
Install / Use
npx skills add elementalsouls/Claude-OSINT --skill osint-autopilotInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
SecuritySupported Platforms
Tags
Our assessment of osint-autopilot
osint-autopilot scores 88/100 on our quality scale, 500th of 867 Security skills we index.
Its SKILL.md is 5.5 KB long, well organised into 11 sections with 3 code examples: a solid amount of guidance for an agent.
With 2,654 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated 30 days ago, so osint-autopilot is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
Safety scan
No issues foundOur scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands.
Automated pattern scan on 2026-09-29. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.
osint-autopilot compared with similar skills
All 4 of these similar skills score higher than osint-autopilot; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| osint-autopilot (this skill)by elementalsouls | 88 | 2.7k | 30d ago | SKILL.md |
| algorithmic-artby anthropics | 100 | 177.9k | 7d ago | SKILL.md |
| pptxby anthropics | 100 | 177.9k | 7d ago | SKILL.md |
| designby nextlevelbuilder | 100 | 130.2k | 8d ago | SKILL.md |
| ui-ux-pro-maxby nextlevelbuilder | 100 | 130.2k | 8d ago | SKILL.md |
Frequently asked questions
- How do I install osint-autopilot?
- Run
npx skills add elementalsouls/Claude-OSINT --skill osint-autopilot. The install tabs above show the steps for each supported agent. - Which AI agents does osint-autopilot work with?
- It is written for Zed, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is osint-autopilot safe to use?
- Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is osint-autopilot still maintained?
- The repository was last updated 30 days ago, so osint-autopilot is actively maintained.
Skill content
View source on GitHubname: osint-autopilot description: End-to-end external OSINT engagement autopilot. Run the FULL osint-methodology pipeline to completion in ONE go for an authorized domain — engagement folder, Stages 1-5 (seed, expansion, enrichment, exposure, convergence), multi-agent per-host content+JS fan-out, headline verification, auto-generated findings, and a consolidated multi-tab .xlsx deliverable. Stops ONLY for Stage 6 (active exploitation) arming and out-of-scope sibling assets. Use whenever asked to "run OSINT / recon / attack-surface" on a target — do NOT deliver a thin passive first pass. version: 1.0 sources: asm_reference_impl, community triggers:
- run OSINT
- run recon
- run the full recon pipeline
- attack surface on
- OSINT autopilot
- full external recon
- end to end recon
- recon to completion
- consolidated OSINT workbook
OSINT Autopilot
Purpose: eliminate the "thin first pass, then user pushes for more" failure. When the user says run OSINT/recon on <domain> (authorized), execute the whole pipeline to completion and hand back the consolidated workbook — no stopping to ask except the two hard gates below.
Read the companion osint-methodology skill for the framework; this skill is the executable runbook. Feedback memory osint-full-pipeline-default governs the default.
Hard gates (the ONLY reasons to stop and ask)
- Authorization — if not already asserted, ask the one scope question, then proceed. (Here it's typically already signed.)
- Stage 6 (active exploitation) — BOLA/IDOR, credential replay, injection confirmation. Never run under autopilot; present the ranked target queue and wait for arming.
- Out-of-scope siblings — a newly-discovered sibling domain/brand (e.g.
<company>.iowhen scope was.com). Flag; don't scan until confirmed.
Everything in Stages 1–5 runs without pausing for questions.
Run sequence
Let S = ~/.claude/skills/osint-autopilot/scripts.
1. Deterministic recon (Stages 1–3 + harvest + breach + ports)
bash $S/recon_pipeline.sh <domain>
Creates ~/Research/engagements/<domain>/ and populates evidence (DNS/WHOIS/RDAP/email-sec, subdomain union via subfinder+certspotter+crt.sh, dig-resolve, HTTP probe, identity fabric, /version disclosure, S3 takeover check, gau+wayback+JS harvest, HudsonRock breach, bounded public-IP port scan), hashes everything, and splits responsive hosts into buckets/bucket-NN.
Host notes baked in: uses dig/curl (ProjectDiscovery dnsx/httpx segfault on this M1 — cgo m1cpu); nmap is time-capped at 10 min so it can't stall.
2. Multi-agent per-host fan-out (Stage 4 exposure)
Read buckets/COUNT and the buckets/bucket-* paths, then launch the workflow (ffuf must be on PATH — go install github.com/ffuf/ffuf/v2@latest if missing):
Workflow({ scriptPath: "<S>/host_enum.workflow.js",
args: { domain:"<domain>", engDir:"~/Research/engagements/<domain>" (absolute),
ffuf:"<gopath>/bin/ffuf", wordlist:"<S>/wordlist.txt",
buckets:[ absolute bucket-00 … bucket-NN ] } })
Pass args as a real JSON object, NOT a stringified one — the harness hands args to the script verbatim; a string makes args.domain/args.buckets undefined and only the synthesize agent runs. The script fails loudly if args are malformed. engDir must be absolute. buckets = absolute paths of every buckets/bucket-* file (read buckets/COUNT).
It fans out ffuf content-discovery + JS/endpoint analysis per bucket (agentType general-purpose), then synthesizes a ranked BOLA/IDOR target queue. Save synthesis to evidence/stage6-content/SYNTHESIS.md.
Optional screenshots: gowitness scan file -f <urls> --screenshot-path evidence/stage6-screens --write-db (Chrome required).
3. Verify headlines yourself (do NOT trust agent output blindly)
Re-curl every CONFIRMED-worthy claim before reporting it: exposed secrets (fetch the JS/vars file), /version disclosures, Cognito/Auth0 config, any "unauth admin 200". Downgrade anything you can't reproduce.
4. Auto-findings + workbook
build_xlsx.py requires the openpyxl pip package (pip install -r $S/requirements.txt if missing).
python3 $S/findings_gen.py <domain> # evidence -> findings/findings.csv (rules engine)
python3 $S/build_xlsx.py <domain> # findings.csv + evidence -> <domain>-osint-consolidated.xlsx
findings_gen.py encodes the rubric (non-prod exposure, CDN/WAF-bypass origins, internal-IP leak, DMARC/SPF, /version disclosure, JS secrets, S3 takeover, identity fabric, breach severity, WordPress, port exposure). Hand-add any nuanced findings the rules miss by editing findings.csv, then re-run build_xlsx.py.
5. Report
Give the consolidated .xlsx path + a short severity summary, then present the two open gates (Stage 6 queue + any out-of-scope siblings). Offer passive CVE mapping against disclosed versions as a next step.
Deliverable
~/Research/engagements/<domain>/:
<domain>-osint-consolidated.xlsx— 9–10 tabs (Summary, Findings, Subdomains, Live Hosts, API Endpoints, Secrets, Ports, Internal-IP-Leak, Screenshots)findings/findings.csv·evidence/**(+.sha256) ·evidence/stage6-content/SYNTHESIS.md·run-log.jsonl
Time budget
Small org (<100 hosts): ~15–25 min wall-clock. Medium (100–1K): ~30–60 min, dominated by the fan-out workflow and gau harvest.
Scale note
The fan-out is ~1 agent per 18 hosts. Keep total agents ≤15 (default guideline); for >270 responsive hosts, raise bucket size in recon_pipeline.sh (split -l) rather than agent count.
Related Skills
algorithmic-art
177.9kCreating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems.
pptx
177.9kUse this skill any time a .pptx or .potx file is involved in any way — as input, output, or both. This includes: creating slide decks, pitch decks, or presentations; reading, parsing, or extracting text from any .pptx or .potx file (even if the extracted content will be used elsewhere, like in an em…
design
130.2kComprehensive design skill: brand identity, design tokens, UI styling, logo generation (55 styles, Gemini, Atlas Cloud, or MuAPI AI), corporate identity program (50 deliverables, CIP mockups), HTML presentations (Chart.js), banner design (22 styles, social/ads/web/print), icon design (15 styles, SVG…
ui-ux-pro-max
130.2kUI/UX design intelligence for web, mobile, and desktop. This skill should be used when designing, building, reviewing, or fixing interfaces, including pages, components, design systems, accessibility, interaction, responsive layout, typography, color, charts, and stack-specific UI implementation.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
