a2a-security-review
Review agent-to-agent (A2A) / multi-agent-system trust: peer identity and authentication, message integrity, capability-negotiation trust, and delegation-chain…
Gather people- and organization-focused OSINT for an authorized social-engineering assessment — org structure, roles, contact patterns, and public footprint that inform realistic phishing/pretext scenarios. Use only within an authorized engagement; focus on assessing
$ npx -y skills add jassics/awesome-claude-security --skill people-osint --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/people-osintContext preview
The summary Claude sees to decide when to auto-load this skill.
Gather people- and organization-focused OSINT for an authorized social-engineering assessment — org structure, roles, contact patterns, and public footprint that inform realistic phishing/pretext scenarios. Use only within an authorized engagement; focus on assessing
name: people-osint description: >- Gather people- and organization-focused OSINT for an authorized social-engineering assessment — org structure, roles, contact patterns, and public footprint that inform realistic phishing/pretext scenarios. Use only within an authorized engagement; focus on assessing susceptibility and improving awareness.
Enough organizational and personnel context to design realistic social-engineering test scenarios (and to inform defensive awareness) — without overcollecting or crossing ethical/legal lines.
to harm or harass individuals. Handle personal data with care; minimize and protect it; respect privacy law.
1. **Structure & roles** — departments, reporting lines, key functions (finance, IT, HR — common phishing targets), and high-value roles. 2. **Contact patterns** — corporate email format, naming conventions, public contact info, out-of-office/role mailboxes. 3. **Public footprint** — professional profiles, conference talks, public posts that reveal tooling, processes, or pretext hooks (events, vendors, projects). 4. **Pretext material** — current initiatives, partners, and vendors that make a believable, testable scenario.
1. Confirm authorization and RoE; define what's in scope and off-limits. 2. Collect organization-level context and the email/naming pattern. 3. Build realistic, role-appropriate scenarios (e.g. vendor/IT/HR themes) for the authorized phishing/vishing test. 4. Keep records minimal and protected.
An assessment-support pack: org/role map · email/naming pattern · candidate pretext themes · suggested target roles (by function, not gratuitous personal detail). Use `security-reporting`; results inform awareness training and email controls.
Stay authorized, public-source, and minimal — this measures and improves resilience, it is not a license to profile or harm people. Finance/IT/HR are common targets; weak SPF/DMARC (see `exposure-discovery`) makes spoofing easier and is a key defensive fix.
A Claude Code plugin marketplace for the full cybersecurity & GenAI-security lifecycle — from recon and threat modeling to detection engineering, GRC, and CISO-level strategy. A pentester knows which OWASP test bends a broken-access-control endpoint.
Repo: jassics/awesome-claude-security
Review agent-to-agent (A2A) / multi-agent-system trust: peer identity and authentication, message integrity, capability-negotiation trust, and delegation-chain…
Test the agent execution harness/runtime itself — LangChain/LangGraph, AutoGen, CrewAI, custom ReAct-style loops, or computer-use/browser-use agents — for…
Assess an autonomous / tool-using AI agent for security end-to-end: tool privileges, autonomy and approval boundaries, excessive agency, memory/state…
Test what an AI agent will actually do without human confirmation, including under injected-goal / prompt-injection scenarios, to validate its autonomy and…
Review the security of MCP (Model Context Protocol) servers/clients an agent uses: server trust tier, tool/resource description and result poisoning,…
Inventory the tools/functions an AI agent can call and audit their privileges, side effects, and approval requirements to find excessive-agency and…