run-claude-osint
Build, validate, and run the claude-osint skills repo — check SKILL.md frontmatter, run the secret_scan.py and h1_reference.py helpers, run…
Operational arsenal for external red-team and bug-bounty reconnaissance. Concrete wordlists (28 Swagger paths, 13 GraphQL paths, 35 high-risk ports, 6 missing-header findings, 15 always-on HTTP checks, 5 SAML paths, cloud bucket permutations, JS guess-paths, vendor product
$ npx -y skills add elementalsouls/Claude-OSINT --skill offensive-osint --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/offensive-osintContext preview
The summary Claude sees to decide when to auto-load this skill.
Operational arsenal for external red-team and bug-bounty reconnaissance. Concrete wordlists (28 Swagger paths, 13 GraphQL paths, 35 high-risk ports, 6 missing-header findings, 15 always-on HTTP checks, 5 SAML paths, cloud bucket permutations, JS guess-paths, vendor product
name: offensive-osint description: "Operational arsenal for external red-team and bug-bounty reconnaissance. Concrete wordlists (28 Swagger paths, 13 GraphQL paths, 35 high-risk ports, 6 missing-header findings, 15 always-on HTTP checks, 5 SAML paths, cloud bucket permutations, JS guess-paths, vendor product fingerprints for Citrix/F5/Pulse/Fortinet/Cisco/PaloAlto/VMware/Exchange, cloud-native service fingerprints, container/K8s exposure paths, CI/CD platform paths, documentation/wiki leak paths, WHOIS/RDAP, DNS record catalog, Wayback CDX recipes), 80-pattern secret-regex catalog (incl. modern AI API keys: Anthropic/OpenAI/HuggingFace/Cloudflare/DigitalOcean/npm/PyPI/Docker Hub/Atlassian/DataDog/Sentry/ngrok; plus a provider-expansion tier: Postman PMAK/GitLab/Square/Shopify/Mailchimp/PagerDuty/Asana/Databricks/Grafana/Terraform Cloud/Fastly/Algolia/Segment/Airtable/GCP+Google OAuth/Azure AD/Facebook OAuth/RubyGems/JFrog/Okta/Slack app-level/Dropbox/Doppler/HashiCorp Vault/Firebase Cloud Messaging), 80+ dork corpus across 9 categories, GitHub code-search dorks, copy-paste curl/httpie probes for every check, post-discovery enumeration workflows (AWS/GitHub/Slack/JWT/PMAK/Anthropic/OpenAI), endpoint interest scoring rubric (0–100), mobile app ownership confidence + APK static-analysis pipeline (acquisition, apktool/aapt2/jadx/androguard decompile, manifest exported-component/deep-link/misconfig extraction, Firebase config, network-security-config, embedded-secret scan), identity-fabric endpoints (Entra/Okta/ADFS/Google/SAML/M365 Teams+SharePoint+OneDrive+OAuth + user-enum), GraphQL field-suggestion enumeration when introspection disabled, 9 read-only secret validators (Postman/AWS/GitHub/Slack/Anthropic/OpenAI/npm/Atlassian/DataDog), Postman workspace search (verified endpoint), Stack Exchange sweep, public SaaS dorks, email security analysis (SPF/DMARC/DKIM/BIMI/MTA-STS/DNSSEC), origin-discovery / CDN bypass techniques, TLS deep audit (sslyze/testssl.sh/JA3/JA4), reverse-DNS sweep + IPv6 enum, vulnerability prioritization data sources (NVD/EPSS/CISA KEV/ExploitDB/Metasploit), 27 attack-path hint templates, 80+ severity-matrix examples, LinkedIn employee enumeration, job posting tech-stack analysis, Slack/Discord workspace discovery, package registry leak hunting (npm/PyPI/Docker Hub/Quay/GHCR), sat imagery for physical recon, tooling quick-install one-liners, sector-specific recon notes (healthcare/finance/ICS-SCADA/IoT/government), runnable stdlib-only secret_scan.py helper, plus the existing tool references for username/email/phone/people/social/breach/infrastructure/crypto/media/geospatial/AI/archiving/automation. Use when you need concrete probe paths, regexes, payloads, scoring rules, curl one-liners, and tool URLs for an authorized external recon engagement." version: 2.2 sources: hackerone_public, community, public_research triggers: - external recon - external red team - red team external - attack surface management - ASM - bug bounty recon - bug bounty - reconnaissance - footprinting - asset discovery - swagger discovery - openapi discovery - graphql introspection - graphql discovery - subdomain enumeration - subdomain takeover - cloud bucket enumeration - bucket enum - S3 enum - GCS enum - Azure blob enum - identity fabric - SSO discovery - IdP fingerprinting - tenant fingerprinting - okta enum - entra enum - azure AD enum - ADFS enum - SAML metadata - mobile recon - APK analysis - mobile attack surface - secret scanning - secret leak - leaked credential - github dorking - google dorking - bing dorking - DDG dorking - postman workspace - stack exchange OSINT - breach lookup - have I been pwned - HudsonRock cavalier - infostealer - dehashed - intelx - shodan recon - censys recon - certificate transparency - crt.sh - JARM - favicon mmh3 - JS endpoint extraction - sourcemap leak - copy paste probes - curl one-liner - email security analysis - SPF DMARC DKIM - origin discovery - CDN bypass - WAF bypass - vendor product fingerprints - Citrix Netscaler - F5 BIG-IP - Pulse Secure - FortiGate - PaloAlto GlobalProtect - Cisco AnyConnect - VMware vCenter - cloud native fingerprint - Lambda function URL - Cloud Run - kubernetes exposure - kubelet - etcd - CI CD exposure - Jenkins recon - GitLab self-hosted - GitHub Actions secrets - documentation leak - Notion public - Confluence anonymous - Trello board - WHOIS RDAP - DNS record catalog - Wayback CDX - LinkedIn enumeration - job posting tech stack - Slack workspace discovery - Discord server discovery - npm token leak - PyPI token leak - Docker Hub leak - sat imagery physical recon - TLS deep audit - JA3 JA4 - reverse DNS sweep - IPv6 enumeration - CVE prioritization - EPSS scoring - CISA KEV - vulnerability prioritization - tooling install - sector specific recon - healthcare DICOM - finance SWIFT - ICS SCADA - Modbus - BACnet - post discovery workflow - JWT triage - AWS key triage - GraphQL field suggestion - Anthropic API key - OpenAI API key - Microsoft 365 deep - Teams federation - SharePoint enum - OneDrive enum - hackerone reference - h1 hacktivity - disclosed reports - community bug reports - prior disclosures - bug bounty reference
> Companion skill: `osint-methodology` (the "how to think" skill). This skill is the "what to reach for." Use them together.
**Use this skill when:**
**Do NOT use this skill when:**
8 Claude skills · 100+ recon capabilities · 80 secret-regex patterns · 80+ dorks · 9 read-only credential validators · 27 attack-path templates · ~10,000 lines of structured tradecraft.
Repo: elementalsouls/Claude-OSINT
Build, validate, and run the claude-osint skills repo — check SKILL.md frontmatter, run the secret_scan.py and h1_reference.py helpers, run…
Organization-grade cloud and supply-chain attack-surface discovery: S3/GCS/Azure Blob bucket discovery via observed-name mining (CNAME/cert-SAN/Wayback) and…
Turns one-shot external recon into a continuous monitoring program. Covers the scheduled re-scan-and-diff loop (baseline snapshot -> interval sleep -> re-scan…
Rigorous, defensible email-spoofability verdict and SPF supply-chain risk analysis computed from published DNS alone. Deepens the record-level…
FAIR-aligned exposure quantification: turns a pile of recon findings into a defensible 0-100 + A-F org risk score (Likelihood x Impact, three ownership-aware…
Organization-grade identity-fabric mapping: tenant/federation fingerprinting and the pre-auth user-ENUMERATION oracle methodology — enumeration and fingerprint…