Skip to content
Security
Skill

/people-osint

Gather people- and organization-focused OSINT for an authorized social-engineering assessment — org structure, roles, contact patterns, and public footprint that inform realistic phishing/pretext scenarios. Use only within an authorized engagement; focus on assessing

From plugin
awesome-claude-security
7111 skills17 agents13 commands1 MCP
Install
$ npx -y skills add jassics/awesome-claude-security --skill people-osint --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/people-osint

Context preview

The summary Claude sees to decide when to auto-load this skill.

Gather people- and organization-focused OSINT for an authorized social-engineering assessment — org structure, roles, contact patterns, and public footprint that inform realistic phishing/pretext scenarios. Use only within an authorized engagement; focus on assessing

SKILL.md

people-osint.SKILL.md
name: people-osint
description: >-
  Gather people- and organization-focused OSINT for an authorized social-engineering
  assessment — org structure, roles, contact patterns, and public footprint that
  inform realistic phishing/pretext scenarios. Use only within an authorized
  engagement; focus on assessing susceptibility and improving awareness.

Goal

Enough organizational and personnel context to design realistic social-engineering test scenarios (and to inform defensive awareness) — without overcollecting or crossing ethical/legal lines.

Scope & ethics first

  • Only within an **authorized** engagement with agreed rules of engagement.
  • Collect from **public** sources; gather the **minimum** needed for the assessment.
  • The objective is to **measure susceptibility and improve awareness/controls**, not

to harm or harass individuals. Handle personal data with care; minimize and protect it; respect privacy law.

What to gather (organization-centric)

1. **Structure & roles** — departments, reporting lines, key functions (finance, IT, HR — common phishing targets), and high-value roles. 2. **Contact patterns** — corporate email format, naming conventions, public contact info, out-of-office/role mailboxes. 3. **Public footprint** — professional profiles, conference talks, public posts that reveal tooling, processes, or pretext hooks (events, vendors, projects). 4. **Pretext material** — current initiatives, partners, and vendors that make a believable, testable scenario.

Steps

1. Confirm authorization and RoE; define what's in scope and off-limits. 2. Collect organization-level context and the email/naming pattern. 3. Build realistic, role-appropriate scenarios (e.g. vendor/IT/HR themes) for the authorized phishing/vishing test. 4. Keep records minimal and protected.

Output

An assessment-support pack: org/role map · email/naming pattern · candidate pretext themes · suggested target roles (by function, not gratuitous personal detail). Use `security-reporting`; results inform awareness training and email controls.

Notes

Stay authorized, public-source, and minimal — this measures and improves resilience, it is not a license to profile or harm people. Finance/IT/HR are common targets; weak SPF/DMARC (see `exposure-discovery`) makes spoofing easier and is a key defensive fix.

Read more
Ships withawesome-claude-security

A Claude Code plugin marketplace for the full cybersecurity & GenAI-security lifecycle — from recon and threat modeling to detection engineering, GRC, and CISO-level strategy. A pentester knows which OWASP test bends a broken-access-control endpoint.

Get the whole plugin

Other skills on awesome-claude-security.