claude-osint
A set of skills for external OSINT recon: methodology, tactical arsenal and deep attack-surface analysis for authorized assessments
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- Runs active external recon against real targets: subdomain enumeration, port scanning, secret hunting
- Executes network tools and scripts on the host
- Usable only with written authorization for the scope
Install
In your terminal, with SkillFoxx CLI
npx skillfoxx add skills/claude-osintDetects the agents on your machine, checks the risk and pins the version.
Other ways to install
Assembled automatically, review before installing.
Run in a terminal in the project folder
npx skills add elementalsouls/claude-osint --skill osint-methodology offensive-osint org-attack-surface email-domain-security exposure-risk-quantification continuous-exposure-monitoring cloud-saas-exposure identity-provider-recon -a claude-code -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Without third-party tools, from commit 13d9204
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/elementalsouls/claude-osint.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/osint-methodology/ /skills/offensive-osint/ /skills/org-attack-surface/ /skills/email-domain-security/ /skills/exposure-risk-quantification/ /skills/continuous-exposure-monitoring/ /skills/cloud-saas-exposure/ /skills/identity-provider-recon/
git -C "$tmp" checkout 13d920413448c026b52ac74efee0f1eb39dd81ff
mkdir -p .claude/skills
cp -R "$tmp/skills/osint-methodology" .claude/skills/osint-methodology
cp -R "$tmp/skills/offensive-osint" .claude/skills/offensive-osint
cp -R "$tmp/skills/org-attack-surface" .claude/skills/org-attack-surface
cp -R "$tmp/skills/email-domain-security" .claude/skills/email-domain-security
cp -R "$tmp/skills/exposure-risk-quantification" .claude/skills/exposure-risk-quantification
cp -R "$tmp/skills/continuous-exposure-monitoring" .claude/skills/continuous-exposure-monitoring
cp -R "$tmp/skills/cloud-saas-exposure" .claude/skills/cloud-saas-exposure
cp -R "$tmp/skills/identity-provider-recon" .claude/skills/identity-provider-reconCommands for macOS and Linux, on Windows run them in Git Bash.
Run in a terminal in the project folder
npx skills add elementalsouls/claude-osint --skill osint-methodology offensive-osint org-attack-surface email-domain-security exposure-risk-quantification continuous-exposure-monitoring cloud-saas-exposure identity-provider-recon -a cursor -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Without third-party tools, from commit 13d9204
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/elementalsouls/claude-osint.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/osint-methodology/ /skills/offensive-osint/ /skills/org-attack-surface/ /skills/email-domain-security/ /skills/exposure-risk-quantification/ /skills/continuous-exposure-monitoring/ /skills/cloud-saas-exposure/ /skills/identity-provider-recon/
git -C "$tmp" checkout 13d920413448c026b52ac74efee0f1eb39dd81ff
mkdir -p .agents/skills
cp -R "$tmp/skills/osint-methodology" .agents/skills/osint-methodology
cp -R "$tmp/skills/offensive-osint" .agents/skills/offensive-osint
cp -R "$tmp/skills/org-attack-surface" .agents/skills/org-attack-surface
cp -R "$tmp/skills/email-domain-security" .agents/skills/email-domain-security
cp -R "$tmp/skills/exposure-risk-quantification" .agents/skills/exposure-risk-quantification
cp -R "$tmp/skills/continuous-exposure-monitoring" .agents/skills/continuous-exposure-monitoring
cp -R "$tmp/skills/cloud-saas-exposure" .agents/skills/cloud-saas-exposure
cp -R "$tmp/skills/identity-provider-recon" .agents/skills/identity-provider-reconCommands for macOS and Linux, on Windows run them in Git Bash.
Run in a terminal in the project folder
npx skills add elementalsouls/claude-osint --skill osint-methodology offensive-osint org-attack-surface email-domain-security exposure-risk-quantification continuous-exposure-monitoring cloud-saas-exposure identity-provider-recon -a github-copilot -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Without third-party tools, from commit 13d9204
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/elementalsouls/claude-osint.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/osint-methodology/ /skills/offensive-osint/ /skills/org-attack-surface/ /skills/email-domain-security/ /skills/exposure-risk-quantification/ /skills/continuous-exposure-monitoring/ /skills/cloud-saas-exposure/ /skills/identity-provider-recon/
git -C "$tmp" checkout 13d920413448c026b52ac74efee0f1eb39dd81ff
mkdir -p .github/skills
cp -R "$tmp/skills/osint-methodology" .github/skills/osint-methodology
cp -R "$tmp/skills/offensive-osint" .github/skills/offensive-osint
cp -R "$tmp/skills/org-attack-surface" .github/skills/org-attack-surface
cp -R "$tmp/skills/email-domain-security" .github/skills/email-domain-security
cp -R "$tmp/skills/exposure-risk-quantification" .github/skills/exposure-risk-quantification
cp -R "$tmp/skills/continuous-exposure-monitoring" .github/skills/continuous-exposure-monitoring
cp -R "$tmp/skills/cloud-saas-exposure" .github/skills/cloud-saas-exposure
cp -R "$tmp/skills/identity-provider-recon" .github/skills/identity-provider-reconCommands for macOS and Linux, on Windows run them in Git Bash.
Run in a terminal in the project folder
npx skills add elementalsouls/claude-osint --skill osint-methodology offensive-osint org-attack-surface email-domain-security exposure-risk-quantification continuous-exposure-monitoring cloud-saas-exposure identity-provider-recon -a codex -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Without third-party tools, from commit 13d9204
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/elementalsouls/claude-osint.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/osint-methodology/ /skills/offensive-osint/ /skills/org-attack-surface/ /skills/email-domain-security/ /skills/exposure-risk-quantification/ /skills/continuous-exposure-monitoring/ /skills/cloud-saas-exposure/ /skills/identity-provider-recon/
git -C "$tmp" checkout 13d920413448c026b52ac74efee0f1eb39dd81ff
mkdir -p .agents/skills
cp -R "$tmp/skills/osint-methodology" .agents/skills/osint-methodology
cp -R "$tmp/skills/offensive-osint" .agents/skills/offensive-osint
cp -R "$tmp/skills/org-attack-surface" .agents/skills/org-attack-surface
cp -R "$tmp/skills/email-domain-security" .agents/skills/email-domain-security
cp -R "$tmp/skills/exposure-risk-quantification" .agents/skills/exposure-risk-quantification
cp -R "$tmp/skills/continuous-exposure-monitoring" .agents/skills/continuous-exposure-monitoring
cp -R "$tmp/skills/cloud-saas-exposure" .agents/skills/cloud-saas-exposure
cp -R "$tmp/skills/identity-provider-recon" .agents/skills/identity-provider-reconCommands for macOS and Linux, on Windows run them in Git Bash.
Run in a terminal in the project folder
npx skills add elementalsouls/claude-osint --skill osint-methodology offensive-osint org-attack-surface email-domain-security exposure-risk-quantification continuous-exposure-monitoring cloud-saas-exposure identity-provider-recon -a gemini-cli -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Without third-party tools, from commit 13d9204
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/elementalsouls/claude-osint.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/osint-methodology/ /skills/offensive-osint/ /skills/org-attack-surface/ /skills/email-domain-security/ /skills/exposure-risk-quantification/ /skills/continuous-exposure-monitoring/ /skills/cloud-saas-exposure/ /skills/identity-provider-recon/
git -C "$tmp" checkout 13d920413448c026b52ac74efee0f1eb39dd81ff
mkdir -p .agents/skills
cp -R "$tmp/skills/osint-methodology" .agents/skills/osint-methodology
cp -R "$tmp/skills/offensive-osint" .agents/skills/offensive-osint
cp -R "$tmp/skills/org-attack-surface" .agents/skills/org-attack-surface
cp -R "$tmp/skills/email-domain-security" .agents/skills/email-domain-security
cp -R "$tmp/skills/exposure-risk-quantification" .agents/skills/exposure-risk-quantification
cp -R "$tmp/skills/continuous-exposure-monitoring" .agents/skills/continuous-exposure-monitoring
cp -R "$tmp/skills/cloud-saas-exposure" .agents/skills/cloud-saas-exposure
cp -R "$tmp/skills/identity-provider-recon" .agents/skills/identity-provider-reconCommands for macOS and Linux, on Windows run them in Git Bash.
Run in a terminal in the project folder
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/elementalsouls/claude-osint.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/osint-methodology/ /skills/offensive-osint/ /skills/org-attack-surface/ /skills/email-domain-security/ /skills/exposure-risk-quantification/ /skills/continuous-exposure-monitoring/ /skills/cloud-saas-exposure/ /skills/identity-provider-recon/
git -C "$tmp" checkout 13d920413448c026b52ac74efee0f1eb39dd81ff
mkdir -p .devin/skills
cp -R "$tmp/skills/osint-methodology" .devin/skills/osint-methodology
cp -R "$tmp/skills/offensive-osint" .devin/skills/offensive-osint
cp -R "$tmp/skills/org-attack-surface" .devin/skills/org-attack-surface
cp -R "$tmp/skills/email-domain-security" .devin/skills/email-domain-security
cp -R "$tmp/skills/exposure-risk-quantification" .devin/skills/exposure-risk-quantification
cp -R "$tmp/skills/continuous-exposure-monitoring" .devin/skills/continuous-exposure-monitoring
cp -R "$tmp/skills/cloud-saas-exposure" .devin/skills/cloud-saas-exposure
cp -R "$tmp/skills/identity-provider-recon" .devin/skills/identity-provider-reconCommands for macOS and Linux, on Windows run them in Git Bash.
Formerly Windsurf.
Run in a terminal in the project folder
npx skills add elementalsouls/claude-osint --skill osint-methodology offensive-osint org-attack-surface email-domain-security exposure-risk-quantification continuous-exposure-monitoring cloud-saas-exposure identity-provider-recon -a cline -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Without third-party tools, from commit 13d9204
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/elementalsouls/claude-osint.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/osint-methodology/ /skills/offensive-osint/ /skills/org-attack-surface/ /skills/email-domain-security/ /skills/exposure-risk-quantification/ /skills/continuous-exposure-monitoring/ /skills/cloud-saas-exposure/ /skills/identity-provider-recon/
git -C "$tmp" checkout 13d920413448c026b52ac74efee0f1eb39dd81ff
mkdir -p .cline/skills
cp -R "$tmp/skills/osint-methodology" .cline/skills/osint-methodology
cp -R "$tmp/skills/offensive-osint" .cline/skills/offensive-osint
cp -R "$tmp/skills/org-attack-surface" .cline/skills/org-attack-surface
cp -R "$tmp/skills/email-domain-security" .cline/skills/email-domain-security
cp -R "$tmp/skills/exposure-risk-quantification" .cline/skills/exposure-risk-quantification
cp -R "$tmp/skills/continuous-exposure-monitoring" .cline/skills/continuous-exposure-monitoring
cp -R "$tmp/skills/cloud-saas-exposure" .cline/skills/cloud-saas-exposure
cp -R "$tmp/skills/identity-provider-recon" .cline/skills/identity-provider-reconCommands for macOS and Linux, on Windows run them in Git Bash.
Run in a terminal in the project folder
npx skills add elementalsouls/claude-osint --skill osint-methodology offensive-osint org-attack-surface email-domain-security exposure-risk-quantification continuous-exposure-monitoring cloud-saas-exposure identity-provider-recon -a roo -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Without third-party tools, from commit 13d9204
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/elementalsouls/claude-osint.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/osint-methodology/ /skills/offensive-osint/ /skills/org-attack-surface/ /skills/email-domain-security/ /skills/exposure-risk-quantification/ /skills/continuous-exposure-monitoring/ /skills/cloud-saas-exposure/ /skills/identity-provider-recon/
git -C "$tmp" checkout 13d920413448c026b52ac74efee0f1eb39dd81ff
mkdir -p .roo/skills
cp -R "$tmp/skills/osint-methodology" .roo/skills/osint-methodology
cp -R "$tmp/skills/offensive-osint" .roo/skills/offensive-osint
cp -R "$tmp/skills/org-attack-surface" .roo/skills/org-attack-surface
cp -R "$tmp/skills/email-domain-security" .roo/skills/email-domain-security
cp -R "$tmp/skills/exposure-risk-quantification" .roo/skills/exposure-risk-quantification
cp -R "$tmp/skills/continuous-exposure-monitoring" .roo/skills/continuous-exposure-monitoring
cp -R "$tmp/skills/cloud-saas-exposure" .roo/skills/cloud-saas-exposure
cp -R "$tmp/skills/identity-provider-recon" .roo/skills/identity-provider-reconCommands for macOS and Linux, on Windows run them in Git Bash.
A fork of Roo Code, same .roo folders.
Run in a terminal in the project folder
npx skills add elementalsouls/claude-osint --skill osint-methodology offensive-osint org-attack-surface email-domain-security exposure-risk-quantification continuous-exposure-monitoring cloud-saas-exposure identity-provider-recon -a opencode -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Without third-party tools, from commit 13d9204
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/elementalsouls/claude-osint.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/osint-methodology/ /skills/offensive-osint/ /skills/org-attack-surface/ /skills/email-domain-security/ /skills/exposure-risk-quantification/ /skills/continuous-exposure-monitoring/ /skills/cloud-saas-exposure/ /skills/identity-provider-recon/
git -C "$tmp" checkout 13d920413448c026b52ac74efee0f1eb39dd81ff
mkdir -p .agents/skills
cp -R "$tmp/skills/osint-methodology" .agents/skills/osint-methodology
cp -R "$tmp/skills/offensive-osint" .agents/skills/offensive-osint
cp -R "$tmp/skills/org-attack-surface" .agents/skills/org-attack-surface
cp -R "$tmp/skills/email-domain-security" .agents/skills/email-domain-security
cp -R "$tmp/skills/exposure-risk-quantification" .agents/skills/exposure-risk-quantification
cp -R "$tmp/skills/continuous-exposure-monitoring" .agents/skills/continuous-exposure-monitoring
cp -R "$tmp/skills/cloud-saas-exposure" .agents/skills/cloud-saas-exposure
cp -R "$tmp/skills/identity-provider-recon" .agents/skills/identity-provider-reconCommands for macOS and Linux, on Windows run them in Git Bash.
Run in a terminal in the project folder
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/elementalsouls/claude-osint.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/osint-methodology/ /skills/offensive-osint/ /skills/org-attack-surface/ /skills/email-domain-security/ /skills/exposure-risk-quantification/ /skills/continuous-exposure-monitoring/ /skills/cloud-saas-exposure/ /skills/identity-provider-recon/
git -C "$tmp" checkout 13d920413448c026b52ac74efee0f1eb39dd81ff
mkdir -p .agents/skills
cp -R "$tmp/skills/osint-methodology" .agents/skills/osint-methodology
cp -R "$tmp/skills/offensive-osint" .agents/skills/offensive-osint
cp -R "$tmp/skills/org-attack-surface" .agents/skills/org-attack-surface
cp -R "$tmp/skills/email-domain-security" .agents/skills/email-domain-security
cp -R "$tmp/skills/exposure-risk-quantification" .agents/skills/exposure-risk-quantification
cp -R "$tmp/skills/continuous-exposure-monitoring" .agents/skills/continuous-exposure-monitoring
cp -R "$tmp/skills/cloud-saas-exposure" .agents/skills/cloud-saas-exposure
cp -R "$tmp/skills/identity-provider-recon" .agents/skills/identity-provider-reconCommands for macOS and Linux, on Windows run them in Git Bash.
Run in a terminal in the project folder
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/elementalsouls/claude-osint.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/osint-methodology/ /skills/offensive-osint/ /skills/org-attack-surface/ /skills/email-domain-security/ /skills/exposure-risk-quantification/ /skills/continuous-exposure-monitoring/ /skills/cloud-saas-exposure/ /skills/identity-provider-recon/
git -C "$tmp" checkout 13d920413448c026b52ac74efee0f1eb39dd81ff
mkdir -p .agents/skills
cp -R "$tmp/skills/osint-methodology" .agents/skills/osint-methodology
cp -R "$tmp/skills/offensive-osint" .agents/skills/offensive-osint
cp -R "$tmp/skills/org-attack-surface" .agents/skills/org-attack-surface
cp -R "$tmp/skills/email-domain-security" .agents/skills/email-domain-security
cp -R "$tmp/skills/exposure-risk-quantification" .agents/skills/exposure-risk-quantification
cp -R "$tmp/skills/continuous-exposure-monitoring" .agents/skills/continuous-exposure-monitoring
cp -R "$tmp/skills/cloud-saas-exposure" .agents/skills/cloud-saas-exposure
cp -R "$tmp/skills/identity-provider-recon" .agents/skills/identity-provider-reconCommands for macOS and Linux, on Windows run them in Git Bash.
Clone the repository, run scripts/sync-skill-content.sh and copy the folders from skills/ into ~/.claude/skills/. To start you can install just the core: osint-methodology and offensive-osint. Work only against targets you have written authorization for.
Other ways from the author
git clone https://github.com/elementalsouls/Claude-OSINT.git
cd Claude-OSINT
./scripts/sync-skill-content.sh
cp -r skills/* ~/.claude/skills/Global install into ~/.claude/skills/. For a single project copy into the project's .claude/skills/. You can install just the core: skills/osint-methodology and skills/offensive-osint.
This is third-party code. Review the repository files before installing.
What it does
The set gives the agent methodology and techniques for external open-source recon on authorized assessments and bug bounty. The core is a pair of skills: a methodology that sets asset-graph discipline, a severity rubric and deliverable templates, and a tactical arsenal with probe paths, secret-hunting regexes, dorks and one-line commands. Organization-grade skills add legal-entity footprint mapping, email spoofability and SPF analysis, quantified risk scoring, continuous exposure monitoring, cloud and supply-chain review, and identity-provider recon. A separate autopilot skill runs the recon pipeline stage by stage and assembles a consolidated workbook, stopping only at hard gates. Active exploitation is never run under autopilot; it requires a separate confirmation. Some skills ship Python scripts for secret scanning and report building.
Who it is for. For offensive security specialists and bug bounty hunters running authorized external recon.
Good fit when
- You need a structured external recon methodology for an authorized assessment
- You need to map an organization's attack surface: domains, netblocks, email security, cloud
- You need to run the recon pipeline and get a consolidated findings workbook
Not a fit when
- You have no written authorization to recon and test the target
- The target or assets are out of the agreed scope
- You need active exploitation, which is outside recon and requires separate confirmation
Example request
Map the attack surface for example.com, scope is agreed, show findings and a consolidated workbookLimitations
The set is intended only for authorized recon, bug bounty and education; the user is responsible for legality and scope. The skills are markdown files, but the pipeline relies on external tools such as subfinder, dnsx, httpx, nmap, ffuf and gowitness; without them some stages are unavailable. The Python scripts need an interpreter and separate packages, for example openpyxl for the workbook. The author notes known issues on Apple M1 and offers workarounds via dig and curl. Auto-generated findings must be verified by hand before they go into a report.
How to disable. Remove the copied skill folders from ~/.claude/skills/ or delete the symlinks. In a claude.ai project remove the uploaded SKILL.md files from the project knowledge.
Security check
- Runs active external recon against real targets: subdomain enumeration, port scanning, secret hunting
- Executes network tools and scripts on the host
- Usable only with written authorization for the scope
README in short
The README describes a library of skills for the Claude skills system, where each skill is a SKILL.md with methodology for one part of the external recon problem. The core is a methodology plus a tactical arsenal, extended by organization-grade skills for footprint mapping, email security, risk scoring, exposure monitoring, cloud and identity-provider recon. Installation is by copying or symlinking into ~/.claude/skills/, with options to upload SKILL.md into claude.ai projects or attach via the API. By default structured SKILL.md outlines ship, and the full text is populated by the sync-skill-content.sh script. Code is MIT, content under a separate license.
SKILL.md
--- name: osint-autopilot description: End-to-end external OSINT engagement autopilot. Run the FULL osint-methodology pipeline to completion in ONE go for an authorized domain - engagement folder, Stages 1-5 (seed, expansion, enrichment, exposure, convergence), multi-agent per-host content+JS fan-out, headline verification, auto-generated findings, and a consolidated multi-tab .xlsx deliverable. Stops ONLY for Stage 6 (active exploitation) arming and out-of-scope sibling assets. version: 1.0 sources: asm_reference_impl, community triggers: - run OSINT - run recon - run the full recon pipeline - attack surface on - OSINT autopilot --- # OSINT Autopilot Purpose: eliminate the thin first pass, then user pushes for more failure. When the user says run OSINT/recon on a domain (authorized), execute the whole pipeline to completion and hand back the consolidated workbook, no stopping to ask except the two hard gates below. ## Hard gates (the ONLY reasons to stop and ask) 1. Authorization - if not already asserted, ask the one scope question, then proceed. 2. Stage 6 (active exploitation) - never run under autopilot; present the ranked target queue and wait for arming. 3. Out-of-scope siblings - flag a newly-discovered sibling domain; do not scan until confirmed.
FAQ
Is this legal?
The set targets authorized recon, bug bounty and education. Recon and testing may only be run against targets you have written authorization for; responsibility lies with the user.
Do I have to install every skill?
No. Each folder is self-contained, so you can install only what you need, for example the core methodology and arsenal.
Related
A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor
NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference
Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install
Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents