{
  "markdown": "<div align=\"center\">\n\n# 🕵️ OSINT Skills\n\n**Open-source intelligence, run by your AI agent.**\n\nReconnaissance · Attribution · GEOINT · Breach checks · Due diligence\n\n[![License: MIT](https://img.shields.io/badge/license-MIT-blue.svg)](LICENSE)\n[![Skills](https://img.shields.io/badge/skills-28-brightgreen.svg)](#workflows--you-type-these)\n[![skills.sh](https://img.shields.io/badge/skills.sh-listed-8A2BE2.svg)](https://www.skills.sh/useosint/osint-skills)\n[![Works with](https://img.shields.io/badge/Cursor%20·%20Claude%20·%20agents-black.svg?logo=anthropic)](#install)\n[![Ethics](https://img.shields.io/badge/authorized%20use%20only-red.svg)](ETHICS.md)\n[![PRs welcome](https://img.shields.io/badge/PRs-welcome-orange.svg)](CONTRIBUTING.md)\n\n</div>\n\n---\n\n28 skills that let Cursor, Claude, and other coding agents actually run an\nopen-source-intelligence investigation — pivot from an email to a breach to a\nreused handle to a real name, geolocate a photo from the pixels, map a\ncompany's subsidiaries — and write it up with sources instead of vibes.\n\nTwo kinds:\n\n- **10 you run by name** — end-to-end workflows for a person, company, domain,\n  username, email, phone, photo, or social account.\n- **18 the agent reaches for on its own** — the individual techniques those\n  workflows lean on (reverse image search, WHOIS, certificate transparency,\n  breach lookups, chronolocation, and so on).\n\nYou point it at a target. It picks the workflow, chains the techniques, and\nhands back a report where every claim has a source and a confidence level.\n\nThese aren't cheat sheets. Every skill carries the tradecraft that separates a\nlead from a finding — where each source lies to you, which results are\nartefacts of how the tool works, and what it takes to call something confirmed.\nEach one ships with `reference/` material too: the query cookbooks, per-country\nindicator guides, registry catalogues, and format tables you'd otherwise keep\nin a browser tab.\n\n## What a run looks like\n\n```\n> recon-a-domain-passively example.com\n\nscope        passive only, no scanning\nwhois        NameCheap, created 2019-03-11, registrant behind privacy guard\ndns          MX → Google Workspace · SPF lists sendgrid + mailgun\ncrt.sh       14 subdomains, incl. staging.example.com and vpn.example.com\nshodan       vpn:443 Fortinet · staging exposes :8080 Jenkins (no auth)\nwayback      2021 team page named 6 staff, since deleted\n\npivoted 3 staff → LinkedIn, flagged the open Jenkins, wrote report.md\n```\n\nIllustrative — a real run depends on the target and which tools you have keys\nfor. The skills are the technique and the tooling; some tools (Shodan, HIBP,\nDeHashed) want their own API key, and free alternatives are called out inline.\n\n## Install\n\n```bash\ngit clone https://github.com/useosint/osint-skills.git\ncd osint-skills\n./install.sh\n```\n\n`install.sh` symlinks all 28 skills into `~/.cursor/skills`, so `git pull` keeps\nthem current. Restart your agent afterward.\n\n| Command | Installs to |\n|---------|-------------|\n| `./install.sh` | `~/.cursor/skills` (symlink) |\n| `./install.sh --copy` | same, but copies |\n| `./install.sh --claude` | `~/.claude/skills` |\n| `./install.sh --target DIR` | anywhere |\n\nFor a single project instead of your whole machine, drop the `skills/` folder\ninto that repo's `.cursor/skills/`.\n\n## Where to start\n\nPick the workflow that matches whatever you're holding. If you don't know,\n`investigate-anything` routes you.\n\n```mermaid\nflowchart TD\n    Q{What do you<br/>already have?}\n    Q -->|a real name| P[find-anyone]\n    Q -->|a company / brand| C[x-ray-a-company]\n    Q -->|a domain or IP| D[recon-a-domain-passively]\n    Q -->|a username| U[hunt-a-handle]\n    Q -->|an email| E[what-an-email-reveals]\n    Q -->|a phone number| PH[whose-number-is-this]\n    Q -->|a photo / video| G[where-was-this-taken]\n    Q -->|a social profile| S[pattern-of-life-from-socials]\n    Q -->|no idea| R([investigate-anything])\n    R -.picks one.-> Q\n    P --> RPT[[write-the-intel-brief]]\n    C --> RPT\n    D --> RPT\n    U --> RPT\n    E --> RPT\n    PH --> RPT\n    G --> RPT\n    S --> RPT\n```\n\n## Workflows — you type these\n\n| Skill | Does |\n|-------|------|\n| `investigate-anything` | Router. Scope gate, collection plan, source grading, and it picks the workflow. |\n| `find-anyone` | Profile an individual — and survive the name-collision problem |\n| `x-ray-a-company` | Due diligence — entity, ownership, people, infra, risk |\n| `recon-a-domain-passively` | Map a domain, site, or IP without sending it a packet |\n| `hunt-a-handle` | Chase a handle across hundreds of platforms, then prove it's the same person |\n| `what-an-email-reveals` | Validate it, find the accounts it registered, pivot to the owner |\n| `whose-number-is-this` | Line type, carrier, VoIP detection, messaging-app exposure |\n| `where-was-this-taken` | Metadata, provenance, geolocation, and time — in that order |\n| `pattern-of-life-from-socials` | Network, content, and posting rhythm — and what that reveals |\n| `write-the-intel-brief` | Turn findings into a sourced brief that separates fact from inference |\n\n## Techniques — the agent pulls these in as needed\n\n| Skill | For |\n|-------|-----|\n| `find-the-original-image` | First publication of an image, across Yandex, Lens, Bing, TinEye |\n| `secrets-in-file-metadata` | GPS, device serials, authors, and edit chains in files and documents |\n| `who-owns-this-domain` | WHOIS/RDAP, DNS, and the vendors an SPF record gives away |\n| `find-hidden-subdomains` | Certificate transparency, passive DNS, and the hosts that no longer resolve |\n| `read-deleted-pages` | Wayback CDX, archive.today, and getting the raw capture |\n| `google-like-a-spy` | Operators that still work, on the engines that still honour them |\n| `secrets-in-git-history` | Author emails, deleted-fork data, and credentials that never touched HEAD |\n| `geolocate-from-pixels` | Bollards, plates, shadows, sun angle — location and time from the frame alone |\n| `investigate-without-getting-made` | Your attribution surface, and the persona that doesn't leak back to you |\n| `what-leaked-about-you` | Breach exposure, k-anonymity lookups, and why you never touch the credential |\n| `follow-the-crypto` | Clustering, change addresses, and the off-ramp where identity attaches |\n| `track-planes-and-ships` | ICAO hex vs tail number, IMO vs MMSI, and who's gone dark |\n| `find-exposed-servers` | Shodan and Censys queries, favicon hashes, origin IPs behind the CDN |\n| `find-leaks-in-the-wild` | Pastes, forums, Telegram — and telling a fresh leak from a recycled combolist |\n| `is-this-photo-real` | Provenance first, pixels last, and why ELA is usually read wrong |\n| `dig-through-data-brokers` | Broker records as leads, plus the FCRA line you don't cross |\n| `who-really-owns-it` | Registries, filings, beneficial ownership, and the nominee problem |\n| `graph-the-network` | A schema, a source on every edge, and the bridging node you'd otherwise miss |\n\n## How a case actually moves\n\nIt's a chain of pivots. One thing you know turns into the next, until the\npicture holds together under more than one source. Start with an email and it\ncan unfold like this:\n\n```mermaid\nflowchart LR\n    E[email] --> B[what-leaked-about-you]\n    E --> V[validate + Gravatar]\n    B --> U[reused username]\n    B --> N[name / fields leaked]\n    U --> A[accounts across platforms]\n    V --> N\n    A --> PH[posted photos]\n    A --> GH[code repos]\n    PH --> GEO[home / work location]\n    N --> PR{{corroborated identity}}\n    GEO --> PR\n    GH --> PR\n    PR --> RPT[[write-the-intel-brief]]\n```\n\nEvery hop is one of the technique skills; nothing gets called a fact off a\nsingle weak match. And a workflow isn't one lookup — `recon-a-domain-passively`, for\nexample, fans out across several techniques at once:\n\n```mermaid\nflowchart TD\n    D([recon-a-domain-passively]) --> W[who-owns-this-domain]\n    D --> CT[find-hidden-subdomains]\n    D --> WB[read-deleted-pages]\n    D --> GH[secrets-in-git-history]\n    CT --> SUB[subdomains]\n    SUB --> SH[find-exposed-servers]\n    W --> OWN[registrant] -.pivot.-> CO([x-ray-a-company])\n    D --> RPT[[write-the-intel-brief]]\n    SH --> RPT\n    WB --> RPT\n    GH --> RPT\n```\n\n## Rules\n\nOSINT is collecting information that is already public, for a legitimate reason.\nThat's legal most places. Logging into someone's accounts, using leaked\npasswords, scanning boxes you don't own, stalking, doxxing — that isn't, and\nit's not what any of this is for.\n\nEvery workflow makes you state scope and authorization before it does anything,\nand stays passive by default. The details are in [ETHICS.md](ETHICS.md). If your\ngoal is to hurt a specific person, these skills aren't for you.\n\n## Contributing\n\nOne folder, one `SKILL.md`, passive-first, every technique backed by a real\ntool and source. [CONTRIBUTING.md](CONTRIBUTING.md) has the rest.\n\n## License\n\n[MIT](LICENSE). No warranty. What you do with it is on you.\n",
  "bytes": 8924,
  "sha": "ff33cb8e1bcf70f1f68841c69ab97aebc3a2a69fb22d47534bbf2d5bd94ab4b9",
  "repo_slug": "useosint/skills",
  "fonte": "repo",
  "truncated": false,
  "api": "https://agentalog.com/api/listings/skl_useosint_skills_track_planes_and_ships_1fffadc1/readme"
}