run-claude-osint
Build, validate, and run the claude-osint skills repo — check SKILL.md frontmatter, run the secret_scan.py and h1_reference.py helpers, run sync-skill-content.sh, run the smoke test
Install / Use
npx skills add elementalsouls/Claude-OSINT --skill run-claude-osintInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
Development & EngineeringSupported Platforms
Tags
Our assessment of run-claude-osint
run-claude-osint scores 88/100 on our quality scale, 1201st of 3,551 Development & Engineering skills we index (top 34%).
Its SKILL.md is 4.8 KB long, well organised into 12 sections with 3 code examples: a solid amount of guidance for an agent.
With 2,654 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated 30 days ago, so run-claude-osint is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
Safety scan
No issues foundOur scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands.
Automated pattern scan on 2026-09-29. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.
run-claude-osint compared with similar skills
All 4 of these similar skills score higher than run-claude-osint; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| run-claude-osint (this skill)by elementalsouls | 88 | 2.7k | 30d ago | SKILL.md |
| ai-job-searchby MadsLorentzen | 100 | 44.5k | 1d ago | CLAUDE.md |
| claude-howtoby luongnv89 | 100 | 41.7k | 3d ago | CLAUDE.md |
| algorithmic-artby anthropics | 100 | 177.9k | 7d ago | SKILL.md |
| pptxby anthropics | 100 | 177.9k | 7d ago | SKILL.md |
Frequently asked questions
- How do I install run-claude-osint?
- Run
npx skills add elementalsouls/Claude-OSINT --skill run-claude-osint. The install tabs above show the steps for each supported agent. - Which AI agents does run-claude-osint work with?
- It is written for Claude Code, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is run-claude-osint safe to use?
- Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is run-claude-osint still maintained?
- The repository was last updated 30 days ago, so run-claude-osint is actively maintained.
Skill content
View source on GitHubname: run-claude-osint description: Build, validate, and run the claude-osint skills repo — check SKILL.md frontmatter, run the secret_scan.py and h1_reference.py helpers, run sync-skill-content.sh, run the smoke test. Use when asked to run, build, test, validate, or smoke-test claude-osint or its OSINT skills/scripts. version: 1.0.0 triggers:
- run claude-osint
- build claude-osint
- test claude-osint
- validate claude-osint
- smoke test claude-osint
- run secret_scan
- run h1_reference
- validate SKILL.md frontmatter
- sync skill content
Run: claude-osint
claude-osint is not an app — it's a Claude skills package. Its product
is two SKILL.md files (skills/offensive-osint/, skills/osint-methodology/)
plus two runnable Python helpers under skills/offensive-osint/scripts/. There
is no GUI, server, or TUI. "Running it" means: the SKILL.md frontmatter parses
and is complete (that's what Claude loads), and the helper scripts work.
The driver is .claude/skills/run-claude-osint/smoke.sh — it does all of
that in one shot. All paths below are relative to the repo root.
Prerequisites
Python 3 with PyYAML (already present on this container). If import yaml fails:
pip install pyyaml # or: apt-get install -y python3-yaml
The helpers are stdlib-only otherwise. h1_reference.py needs outbound HTTPS to
hackerone.com. No build step, no npm install — nothing to compile.
Run (agent path) — the driver
From the repo root:
.claude/skills/run-claude-osint/smoke.sh # full smoke (exits 0 on pass)
.claude/skills/run-claude-osint/smoke.sh --no-net # skip the HackerOne live check
It runs six checks and prints a ==> PASS / ==> FAIL line (exit 0 / 1):
py_compileboth helpers.secret_scan.pydetects AWS key + JWT from stdin (the CI canaries).secret_scan.pyrecursively scansskills/and emits JSONL (~11 findings — example tokens in the SKILL.md docs).- Every
skills/*/SKILL.mdhas valid YAML frontmatter withname/description/version/triggersand ≥5 triggers. sync-skill-content.sh --checkexits 0.h1_reference.pyfetches one live disclosed report (non-fatal if offline).
Run individual pieces
Verified this session:
# Secret scanner — stdin
printf 'AKIA…[redacted]\n' | python3 skills/offensive-osint/scripts/secret_scan.py
# -> {"pattern": "AWS_ACCESS_KEY", "severity": "critical", ...}
# Secret scanner — scan a directory tree (JSONL, one finding per line)
python3 skills/offensive-osint/scripts/secret_scan.py skills/
# HackerOne reference helper (needs network)
python3 skills/offensive-osint/scripts/h1_reference.py --top-voted --limit 3
python3 skills/offensive-osint/scripts/h1_reference.py --top-bounty --limit 3
python3 skills/offensive-osint/scripts/h1_reference.py --top-voted --query "XSS" --pages 3
# Install the skills for Claude to load
cp -r skills/* ~/.claude/skills/
Test
CI (.github/workflows/lint.yml) runs four jobs: markdown lint
(markdownlint-cli2), the frontmatter check, the secret_scan.py smoke, and
shellcheck ./scripts. smoke.sh covers the latter two plus the helpers
directly. markdownlint-cli2 and shellcheck are not installed on this
container; install with npm i -g markdownlint-cli2 / apt-get install -y shellcheck if you need to reproduce those jobs locally.
Gotchas
sync-skill-content.shis a no-op in a fresh clone. It copies fromdocs/full-skills/, which is not in the repo — the script prints "⚠ Source missing … Skipping" and exits 0. Theskills/*/SKILL.mdfiles are already the full inline content (offensive-osint ≈ 4,200 lines), so you do not need to run sync after cloning. Don't be alarmed by the warnings.secret_scan.pyskips its own findings as noise filters. It excludes.git,node_modules,__pycache__,.venv,dist,build,.cacheand any file >10 MB. Scanningskills/returns the example/doc tokens (~11), not real secrets.h1_reference.pyhits an undocumented public GraphQL endpoint. It works unauthenticated but is sensitive to HackerOne-side changes and rate limits; treat a failure there as environmental, not a repo bug (hence non-fatal in the driver). It caps at 50 results/page — use--pages Nfor breadth.- No screenshot / no window — this repo has no visual surface. If a request
asks to "see it run," that means the
smoke.shPASS output, not a GUI.
Troubleshooting
| Symptom | Fix |
|---|---|
| ModuleNotFoundError: No module named 'yaml' in check [4] | pip install pyyaml (only the frontmatter check needs it). |
| Check [6] shows ~ no network / HackerOne unreachable | Expected when egress is blocked; run with --no-net to silence. Driver still passes. |
| sync --check shows "Source missing" | Expected — see Gotchas. Not a failure; exit code is 0. |
Related Skills
ai-job-search
44.5kThe job search that runs on your machine. AI job application framework built on Claude Code: evaluate postings, tailor CVs, write cover letters, prep interviews. Fork it and own it.
claude-howto
41.7kA visual, example-driven guide to Claude Code — from basic concepts to advanced agents, with copy-paste templates that bring immediate value.
algorithmic-art
177.9kCreating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems.
pptx
177.9kUse this skill any time a .pptx or .potx file is involved in any way — as input, output, or both. This includes: creating slide decks, pitch decks, or presentations; reading, parsing, or extracting text from any .pptx or .potx file (even if the extracted content will be used elsewhere, like in an em…
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
