Skip to content
Security
Skill

/offensive-osint

Router for the Offensive OSINT arsenal. Dispatches to focused sub-skills by task type. Covers the full external red-team surface: asset discovery, web enumeration, identity/SSO, secrets/dorks, post-credential workflows, cloud/infra, people/breach intel, and analysis/reporting.

From plugin
outrider-recon
1211 skills1 MCP
Install
$ npx -y skills add Ap6pack/outrider-recon --skill offensive-osint --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/offensive-osint

Context preview

The summary Claude sees to decide when to auto-load this skill.

Router for the Offensive OSINT arsenal. Dispatches to focused sub-skills by task type. Covers the full external red-team surface: asset discovery, web enumeration, identity/SSO, secrets/dorks, post-credential workflows, cloud/infra, people/breach intel, and analysis/reporting.

SKILL.md

offensive-osint.SKILL.md
name: offensive-osint
description: "Router for the Offensive OSINT arsenal. Dispatches to focused sub-skills by task type. Covers the full external red-team surface: asset discovery, web enumeration, identity/SSO, secrets/dorks, post-credential workflows, cloud/infra, people/breach intel, and analysis/reporting. Companion to osint-methodology. Use for any authorized external recon, bug bounty, or ASM engagement."
when_to_use: "Use to start, continue, or pick up any authorized external recon, red-team, attack-surface-management (ASM), or bug-bounty engagement — footprinting, asset discovery, or assessing a new target — then dispatch to the focused sub-skill for the task."

Offensive OSINT — Arsenal Router

> Companion: `osint-methodology` — pipeline stages, triage rules, severity rubric. Load it alongside this router at the start of every session.

**Scope gate:** Authorized targets only. When scope is unclear, ask once before proceeding.

---

BEHAVIORAL CONTRACT

**When triggered:** Any external recon, bug bounty, ASM engagement, or general "where do I start" offensive OSINT request.

**Execute:**

1. Load `osint-methodology` — identify the pipeline stage and scope. 2. Match the current task to a sub-skill using the sub-skill map below. 3. Load that sub-skill and begin execution immediately. 4. Propose the next concrete action without waiting to be asked. 5. When one sub-skill's work completes, chain to the next relevant sub-skill autonomously — follow the pipeline priority order from `osint-methodology` §7.1.

**Output:** Delegation to the appropriate sub-skill(s). This router produces no findings itself.

**Gating rules:** Authorized targets only. When scope is unclear, ask once before proceeding. Hard rules (below) are always-on across all sub-skills.

**Chain to:** Autonomously chain through sub-skills following `osint-methodology` §7.1 priority order: breaches → GitHub recon → misconfig sweep → cloud buckets → ports → email OSINT → web tech → Wayback → DNS/email security → certs/TLS → ASN/reverse DNS → typosquats.

---

Sub-skill map

Load the sub-skill that matches the current task. Each is self-contained and under 500 lines.

| Task | Sub-skill to load | | ----------------------------------------------------------------------------------------- | ------------------------ | | Subdomains, ASN/BGP, DNS, CT, WHOIS/RDAP, wordlists | `recon-asset-discovery` | | Web surface: Swagger/GraphQL paths, curl probes, Wayback, Postman, endpoint scoring | `web-surface` | | IdP fingerprinting, Entra/Okta/ADFS/SAML, M365 deep enum, LinkedIn employee enum | `identity-fabric` | | Secret regexes, dork corpus, GitHub code-search dorks, read-only validators | `secrets-and-dorks` | | Post-credential: JWT triage, AWS IAM enum, GitHub scope enum, Slack workspace enum | `post-discovery` | | Cloud-native fingerprints, K8s/container, CI/CD exposure, infra OSINT | `cloud-and-infra` | | Username/email/phone, breach data, HudsonRock, Slack/Discord/Telegram, package registries | `people-breach-intel` | | Scoring rubrics, attack-path hints, severity matrix, AI-assisted OSINT, archiving | `analysis-and-reporting` | | Report generation: bug-bounty submission, client deliverable, vulnerability report | `report-template` |

---

Session start checklist

1. Load `osint-methodology` — identify the pipeline stage and scope. 2. Load the sub-skill matching the current task from the map above. 3. Propose the next concrete action without waiting to be asked.

---

Hard rules (always-on, all sub-skills)

  • Never report a bypass without demonstrated impact.
  • Run read-only validators (`secrets-and-dorks`) before escalating any credential finding.
  • `post-discovery` is gated — confirm read-only validation passes first.
  • No destructive probes. No active scanning outside explicit written scope.

Structured Outrider run contract

Follow the shared run-contract instructions in `../_shared/run-contract.md`.

  • Contract skill identifier: `offensive-osint`.
  • Consume `skill_request` version 1 and produce `skill_result` version 1 when participating in an Outrider run.
  • Use evidence IDs for all claims; do not cite unregistered local paths as claim evidence.
  • Discoveries are observations and do not expand scope or approval.
  • Do not claim final finding validation; use `finding_candidate` only when a human-reviewed candidate should be handed off.
  • Do not directly edit `manifest.json`, `scope.yaml`, `run.jsonl`, `evidence.jsonl`, or `approvals.jsonl`.
  • Use policy-gated MCP with the explicit `run_dir`; the Python control layer and MCP boundary must reevaluate current controls.
  • Router role: this skill may select another shipped skill while retaining the same `run_id` and request context.
  • Router role: do not invent unknown skill names, bypass contract validation, or aggregate unsupported narrative into a validated finding.
Read more
Ships withoutrider-recon

Claude-native external recon and attack-surface management for authorized bug bounty, pentest, and security teams. Outrider turns public, read-only recon signals into prioritized, evidence-backed leads.

Get the whole plugin

Other skills on outrider-recon.