Sep 11, 2026

claude-osint: 8 Skills That Turn Claude Into an Authorized Recon Analyst

A 2,583-star library of eight SKILL.md files that give Claude external-recon methodology for assets you own or are authorized to assess, with hard boundaries against active exploitation.

#tutorial#security#agent-tools

External recon on an authorized target means juggling dozens of tools, wordlists, and regex catalogs, plus knowing which check matters for which domain. claude-osint packs that tradecraft into eight markdown skill files, so Claude applies the methodology on demand instead of you pasting checklists into a chat window.

Why This Skill Matters

The 2,583-star repo is organized as a core pair plus six depth skills. osint-methodology covers how to think — a 6-stage recon pipeline, asset-graph discipline, a severity rubric, and reporting templates. offensive-osint covers what to reach for — probe paths, regexes, scoring rules, and tool URLs. The six organization-grade depth skills handle enterprise-scale questions: org-attack-surface (legal entity to owned footprint), email-domain-security (spoofability verdicts and SPF supply-chain analysis), exposure-risk-quantification, continuous-exposure-monitoring, cloud-saas-exposure, and identity-provider-recon.

By the README's own inventory, that adds up to 100+ recon capabilities across 13 domains, 80 secret-regex patterns, 80+ dorks, 9 read-only credential validators, and 27 attack-path templates. The library is explicitly scoped to assets you own or have written authorization to assess, and the README states it excludes active exploitation, post-exploitation, credential submission, token forging or replay, and malware development.

Installation

For Claude Code, the README's install path is a clone plus a sync script:

git clone https://github.com/elementalsouls/Claude-OSINT.git
cd Claude-OSINT
chmod +x ./scripts/sync-skill-content.sh
./scripts/sync-skill-content.sh
mkdir -p ~/.claude/skills
cp -r skills/* ~/.claude/skills/

Skills then auto-load when a session touches on their trigger phrases. If you only want the recon backbone without the depth skills, copy just osint-methodology and offensive-osint. For a single-session setup, pipe one skill straight into Claude: cat skills/offensive-osint/SKILL.md | claude --system-file -. On Claude.ai or the API, paste a SKILL.md into a project's system prompt.

Real Workflow: Audit Your Own Domain's Email Security

  1. After installing, start a Claude Code session and point it at a domain you control:
Use the email-domain-security skill on my own domain, example.com.
Give me a composite spoofability verdict and the full email-security audit.
  1. The skill produces a composite spoofability verdict covering envelope versus header-From alignment, on the principle the README states explicitly: an SPF -all policy alone is not spoof-proof, and only DMARC governs.

  2. It then checks the SPF supply chain — the RFC 7208 limit of 10 DNS lookups that turns a deep include chain into a PermError, and dead includes that could be taken over. The offensive-osint skill's email-security checks cover SPF, DMARC, DKIM, BIMI, MTA-STS, TLS-RPT, and DNSSEC.

  3. Findings arrive with severity, confidence, and evidence, following the methodology skill's rubric of CRITICAL/HIGH/MED/LOW/INFO plus escalation guidance.

A second workflow: an authorized bug-bounty recon run. The methodology skill drives a 6-stage pipeline with time-budget profiles for 1 hour, 4 hours, 1 day, or 1 week, and the repo ships four end-to-end walkthroughs under examples/ (quick recon, bug bounty, M365 deep dive, secret hunting).

Tips

  • Start with the core pair if the depth skills are more enterprise than your engagement needs — the README explicitly blesses that split.
  • The SKILL.md files are plain markdown. The README suggests reading them as a personal cheat-sheet even without Claude.
  • Reuse has terms: code is MIT, but the content — methodology, wordlists, regex catalogs, rubrics — is CC BY 4.0 and requires credit.
  • The repo reports 56/56 pass on its own 56-prompt self-evaluation. That is the project's number about itself, not an independent certification.

When Not to Use This

Not for targets you do not own or lack written authorization to assess — the README frames the library around red-team rules of engagement, bug-bounty scope, and ASM contracts, and the built-in scope-check is a soft guard, not your permission slip. And it stops at reconnaissance: active exploitation, post-exploitation, and credential submission are explicitly excluded, so look elsewhere for those (authorized) phases. For a one-off SPF record check, plain DNS tooling is still faster than installing a skill library.


See the leaderboard for more skills.