Sep 11, 2026
claude-osint: 8 Skills That Turn Claude Into an Authorized Recon Analyst
A 2,583-star library of eight SKILL.md files that give Claude external-recon methodology for assets you own or are authorized to assess, with hard boundaries against active exploitation.
External recon on an authorized target means juggling dozens of tools, wordlists, and regex catalogs, plus knowing which check matters for which domain. claude-osint packs that tradecraft into eight markdown skill files, so Claude applies the methodology on demand instead of you pasting checklists into a chat window.
Why This Skill Matters
The 2,583-star repo is organized as a core pair plus six depth skills. osint-methodology covers how to think — a 6-stage recon pipeline, asset-graph discipline, a severity rubric, and reporting templates. offensive-osint covers what to reach for — probe paths, regexes, scoring rules, and tool URLs. The six organization-grade depth skills handle enterprise-scale questions: org-attack-surface (legal entity to owned footprint), email-domain-security (spoofability verdicts and SPF supply-chain analysis), exposure-risk-quantification, continuous-exposure-monitoring, cloud-saas-exposure, and identity-provider-recon.
By the README's own inventory, that adds up to 100+ recon capabilities across 13 domains, 80 secret-regex patterns, 80+ dorks, 9 read-only credential validators, and 27 attack-path templates. The library is explicitly scoped to assets you own or have written authorization to assess, and the README states it excludes active exploitation, post-exploitation, credential submission, token forging or replay, and malware development.
Installation
For Claude Code, the README's install path is a clone plus a sync script:
git clone https://github.com/elementalsouls/Claude-OSINT.git
cd Claude-OSINT
chmod +x ./scripts/sync-skill-content.sh
./scripts/sync-skill-content.sh
mkdir -p ~/.claude/skills
cp -r skills/* ~/.claude/skills/
Skills then auto-load when a session touches on their trigger phrases. If you only want the recon backbone without the depth skills, copy just osint-methodology and offensive-osint. For a single-session setup, pipe one skill straight into Claude: cat skills/offensive-osint/SKILL.md | claude --system-file -. On Claude.ai or the API, paste a SKILL.md into a project's system prompt.
Real Workflow: Audit Your Own Domain's Email Security
- After installing, start a Claude Code session and point it at a domain you control:
Use the email-domain-security skill on my own domain, example.com.
Give me a composite spoofability verdict and the full email-security audit.
-
The skill produces a composite spoofability verdict covering envelope versus header-From alignment, on the principle the README states explicitly: an SPF
-allpolicy alone is not spoof-proof, and only DMARC governs. -
It then checks the SPF supply chain — the RFC 7208 limit of 10 DNS lookups that turns a deep include chain into a PermError, and dead includes that could be taken over. The
offensive-osintskill's email-security checks cover SPF, DMARC, DKIM, BIMI, MTA-STS, TLS-RPT, and DNSSEC. -
Findings arrive with severity, confidence, and evidence, following the methodology skill's rubric of CRITICAL/HIGH/MED/LOW/INFO plus escalation guidance.
A second workflow: an authorized bug-bounty recon run. The methodology skill drives a 6-stage pipeline with time-budget profiles for 1 hour, 4 hours, 1 day, or 1 week, and the repo ships four end-to-end walkthroughs under examples/ (quick recon, bug bounty, M365 deep dive, secret hunting).
Tips
- Start with the core pair if the depth skills are more enterprise than your engagement needs — the README explicitly blesses that split.
- The
SKILL.mdfiles are plain markdown. The README suggests reading them as a personal cheat-sheet even without Claude. - Reuse has terms: code is MIT, but the content — methodology, wordlists, regex catalogs, rubrics — is CC BY 4.0 and requires credit.
- The repo reports 56/56 pass on its own 56-prompt self-evaluation. That is the project's number about itself, not an independent certification.
When Not to Use This
Not for targets you do not own or lack written authorization to assess — the README frames the library around red-team rules of engagement, bug-bounty scope, and ASM contracts, and the built-in scope-check is a soft guard, not your permission slip. And it stops at reconnaissance: active exploitation, post-exploitation, and credential submission are explicitly excluded, so look elsewhere for those (authorized) phases. For a one-off SPF record check, plain DNS tooling is still faster than installing a skill library.
See the leaderboard for more skills.