Gather and correlate open source intelligence from public sources for authorized investigations, threat intelligence, and attack surface assessment.

MITAuto-check: notesSecurity

Install Osint Recon

skills CLI
$ npx skills add briiirussell/cybersecurity-skills --skill osint-recon -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install briiirussell/cybersecurity-skills osint-recon --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/briiirussell/cybersecurity-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/osint-recon .claude/skills/osint-recon && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
osint-recon
GitHub stars
413
Token cost
~1.1k tokens
SKILL.md length
397 words
Files
1
Skills in repo
25
Repo updated
First seen
Licence
MIT

At a glance

Gather and correlate open source intelligence from public sources for authorized investigations, threat intelligence, and attack surface assessment.

  • Works in 3 steps: The investigation has a legitimate… → You are only gathering publicly… → Results will not be used for harassment,…
  • The user mentions OSINT
  • SKILL.md covers Ethics Check, Collection Techniques, Analysis and Output Format, plus 2 more sections
  • Calls curl and jq; reaches crt.sh

What it does

Osint Recon is an agent skill from briiirussell/cybersecurity-skills. Gather and correlate open source intelligence from public sources for authorized investigations, threat intelligence, and attack surface assessment. Use when the user mentions 'OSINT,' 'open source intelligence,' 'digital footprint,' 'public records,' 'threat intelligence,' 'investigate a domain,' or needs to research a target using publicly available data.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering OSINT. The repository describes itself as: Cybersecurity skills for AI coding agents (Claude Code, Cursor, Codex). The licence is MIT.

When your agent uses it

  • The user mentions OSINT
  • Open source intelligence
  • Digital footprint
  • Threat intelligence

Example prompts

  • “OSINT,”
  • “open source intelligence,”
  • “digital footprint,”
  • “/osint-recon”

Requirements

  • Pre-approved tools (allowed-tools): Bash, WebSearch, WebFetch, Read, Write

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. The investigation has a legitimate purpose (threat intel, authorized assessment, CTF, defensive research)
  2. You are only gathering publicly available information
  3. Results will not be used for harassment, stalking, or doxing

What it can do on your machine

Read from SKILL.md and the folder at commit c9ade03. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • WebSearch
    • WebFetch
    • Read
    • Write

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • crt.sh

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Osint Recon loads about 1.1k tokens when it runs. Until then it costs about 93 tokens; SKILL.md has 397 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~93
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, WebSearch, WebFetch, Read, Write

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from briiirussell/cybersecurity-skills at commit c9ade03, republished under its MIT licence (© briiirussell). 397 words, ~1,150 tokens.

Download SKILL.mdSave it as .claude/skills/osint-recon/SKILL.md (or your agent's skills folder).
name
osint-recon
description
Gather and correlate open source intelligence from public sources for authorized investigations, threat intelligence, and attack surface assessment. Use when the user mentions 'OSINT,' 'open source intelligence,' 'digital footprint,' 'public records,' 'threat intelligence,' 'investigate a domain,' or needs to research a target using publicly available data.
allowed-tools
Bash, WebSearch, WebFetch, Read, Write

OSINT Recon — Open Source Intelligence Gathering

Systematically gather, analyze, and correlate publicly available information from open sources.

Cross-references: recon for the active/passive target-mapping pass against an authorized system (DNS, ports, fingerprinting) — osint-recon focuses on people, organizations, leaked data, and historical artifacts; the two pair naturally. breach-patterns for ingesting public breach intelligence into your own preemptive assessments. incident-triage if OSINT surfaces evidence the user is already compromised.

Ethics Check

Before proceeding, confirm:

  1. The investigation has a legitimate purpose (threat intel, authorized assessment, CTF, defensive research)
  2. You are only gathering publicly available information
  3. Results will not be used for harassment, stalking, or doxing

Refuse requests that target individuals for harassment or aggregate private information beyond what the objective requires.

Collection Techniques

Domain and Infrastructure OSINT

Run these to map a target's infrastructure:

bash
whois <domain>                  # Registration data
dig any <domain>                # DNS records

Query certificate transparency for subdomains:

bash
curl -s "https://crt.sh/?q=%25.<domain>&output=json" | jq -r '.[].name_value' | sort -u

Additional sources: SecurityTrails, DNSDumpster, ipinfo.io, bgp.he.net, Wayback Machine, Shodan, Censys.

Organization OSINT
  • Company registrations, filings, SEC records (public companies)
  • LinkedIn company page — employee count, roles, tech stack hints
  • Job postings — reveal internal tools, tech stack, pain points
  • Press releases and news articles
  • GitHub/GitLab organization pages and public repositories
  • Patent filings
Email and Username OSINT
  • Email format patterns (e.g., first.last@domain.com)
  • HaveIBeenPwned — check for breach exposure (check only, never distribute breach data)
  • PGP key servers for email discovery
  • Gravatar lookups for email-to-identity correlation
Show full SKILL.md (178 more words)Show less
Document and File OSINT
  • Extract metadata from public documents: exiftool <file> reveals author, software, GPS, timestamps
  • Google dorking: site:<domain> filetype:pdf, site:<domain> filetype:xlsx
  • Pastebin and code paste site monitoring
  • Public cloud storage enumeration (S3 buckets, GCS buckets with predictable names)
Threat Intelligence
  • CVE databases for the target's technology stack
  • Exploit databases (exploit-db, searchsploit)
  • Threat feeds and IOC databases (VirusTotal, MalwareBazaar, OTX)
  • Abuse contact databases

Analysis

  • Cross-reference findings across multiple sources
  • Validate information with at least two independent sources
  • Build a timeline of events when investigating incidents
  • Map relationships between entities (people, domains, IPs, organizations)
  • Rate confidence: High (multiple corroborating sources), Medium (single reliable source), Low (unverified)

Output Format

markdown
# OSINT Report
## Objective: [what we're investigating and why]
## Target: [entity/domain/person]
## Date: [date]

### Collection Summary
| Source | Findings | Confidence |
|--------|----------|------------|

### Key Findings

#### Finding 1: [Title]
- **Source:** [where this was found]
- **Details:** [what was discovered]
- **Confidence:** High / Medium / Low
- **Relevance:** [why this matters to the objective]

### Correlations
[How different findings connect to each other]

### Intelligence Gaps
[What we couldn't find or verify]

### Recommendations
[Next steps and actionable intelligence]

Boundaries

  • Only use publicly available sources
  • Never attempt to access private or authenticated systems
  • Do not aggregate PII beyond what is necessary for the stated objective
  • Attribute all findings to their source
  • Rate confidence levels honestly — do not overstate certainty
  • If a finding could cause harm if misused, note the sensitivity
  • Refuse requests for doxing, stalking, or unauthorized surveillance

References

  • OSINT Framework (osintframework.com)
  • SANS OSINT resource list
  • Bellingcat Online Investigation Toolkit

© briiirussell, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/osint-recon of briiirussell/cybersecurity-skills.

Open the folder on GitHubat commit c9ade03

Compare with similar skills

Osint Recon next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Osint Recon compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Osint Recon this skillbriiirussell/cybersecurity-skills413—~1.1kAutomated safety check: NotesMIT
Metabigor OSINT Reconj3ssie/metabigor1.9k—~2.4kAutomated safety check: PassMIT
Ctf Osintljagiello/ctf-skills3.4k1 repos~2.3kAutomated safety check: NotesMIT
ShadowBroker Intelligence ClientBigBodyCobain/Shadowbroker11k—~8.9kAutomated safety check: WarnAGPL-3.0
Awesome Osint Operatorshoyann/RZK-The-Hunter141—~4.8kAutomated safety check: PassCC-BY-SA-4.0
Run Claude Osintelementalsouls/Claude-OSINT2.8k—~1.2kAutomated safety check: PassMIT

Similar skills

  • Metabigor OSINT Recon

    j3ssie/metabigor

    Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys.

    1.9k GitHub stars~2.4k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Ctf Osint

    ljagiello/ctf-skills

    Provides open source intelligence techniques for CTF challenges.

    3.4k GitHub starsUsed in 1 repo~2.3k tokens
    SecurityAuto-check: notes
  • ShadowBroker Intelligence Client

    BigBodyCobain/Shadowbroker

    Lets an agent query a ShadowBroker OSINT platform for tracked flights, ships, satellites and news, and place its findings on the map as intel pins.

    11k GitHub stars~8.9k tokensUpdated yesterday
    SecurityAuto-check: warnings
  • Awesome Osint Operator

    shoyann/RZK-The-Hunter

    Ethical, evidence-first OSINT planning, tool selection, verification, monitoring, reporting, and guarded official wanted/fugitive-person location intelligence using a structured catalog adapted from…

    141 GitHub stars~4.8k tokensUpdated 3 days ago
    SecurityAuto-check passed
  • Run Claude Osint

    elementalsouls/Claude-OSINT

    Build, validate, and run the claude-osint skills repo — check SKILL.md frontmatter, run the secretscan.py and h1reference.py helpers, run sync-skill-content.sh, run the smoke test.

    2.8k GitHub stars~1.2k tokensUpdated yesterday
    SecurityAuto-check passed
  • Osint

    smixs/osint-skill

    Conduct deep OSINT research on individuals. An agent skill from smixs/osint-skill.

    141 GitHub stars~5.5k tokensUpdated 7 mo ago
    SecurityAuto-check passed

More from briiirussell/cybersecurity-skills

All 25 skills in this repo
  • AI Risk Management

    briiirussell/cybersecurity-skills

    Apply the NIST AI Risk Management Framework (AI RMF 1.0) and adjacent guidance to AI / ML systems — model lifecycle governance, fairness and bias evaluation, robustness, transparency…

    413 GitHub stars~3.7k tokensUpdated 4 mo ago
    Auto-check: notes
  • API Audit

    briiirussell/cybersecurity-skills

    Audit REST, GraphQL, and RPC APIs against the OWASP API Security Top 10 (2023).

    413 GitHub stars~2.8k tokensUpdated 4 mo ago
    Auto-check: notes
  • Breach Patterns

    briiirussell/cybersecurity-skills

    Learn from public breach disclosures — extract the audit question each one implies and check your own stack.

    413 GitHub stars~3.5k tokensUpdated 4 mo ago
    Auto-check: notes
  • Cloud Audit

    briiirussell/cybersecurity-skills

    Audit cloud infrastructure (AWS, GCP, Azure) for misconfigurations, excessive permissions, and security gaps.

    413 GitHub stars~1.3k tokensUpdated 4 mo ago
    Auto-check: notes
  • Container Audit

    briiirussell/cybersecurity-skills

    Audit container images, Dockerfiles, and Kubernetes manifests for misconfigurations, excessive privileges, exposed secrets, and runtime risks.

    413 GitHub stars~2.5k tokensUpdated 4 mo ago
    Auto-check: notes
  • Crypto Audit

    briiirussell/cybersecurity-skills

    Audit cryptography implementation — algorithm choice, key sizes, KDF parameters, IV/nonce handling, signature verification, randomness, TLS configuration, and key rotation.

    413 GitHub stars~2.8k tokensUpdated 4 mo ago
    Auto-check: notes

Categories

Questions about Osint Recon

What does Osint Recon do?

Gather and correlate open source intelligence from public sources for authorized investigations, threat intelligence, and attack surface assessment. Osint Recon is an agent skill from briiirussell/cybersecurity-skills. Gather and correlate open source intelligence from public sources for authorized investigations, threat intelligence, and attack surface assessment.

When should I use Osint Recon?

Osint Recon fits situations like: the user mentions OSINT; open source intelligence; digital footprint; threat intelligence.

How do I install Osint Recon in Claude Code?

Run `npx skills add briiirussell/cybersecurity-skills --skill osint-recon -a claude-code`. Or copy the skill folder (skills/osint-recon in briiirussell/cybersecurity-skills) into .claude/skills/osint-recon in your project. Claude Code loads it when a task matches its description.

How do I install Osint Recon in Codex?

Run `npx skills add briiirussell/cybersecurity-skills --skill osint-recon -a codex`. Or copy the skill folder (skills/osint-recon in briiirussell/cybersecurity-skills) into .agents/skills/osint-recon in your project. Codex loads it when a task matches its description.

Can I use Osint Recon in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add briiirussell/cybersecurity-skills --skill osint-recon -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/osint-recon, .gemini/skills/osint-recon, .github/skills/osint-recon and .opencode/skills/osint-recon in your project.

What does Osint Recon need to run?

Going by SKILL.md and its folder, Osint Recon needs the command-line tools its instructions call (curl and jq). Its frontmatter pre-approves these tools: Bash, WebSearch, WebFetch, Read, Write.

Does Osint Recon access the network?

SKILL.md names 1 domain. In commands or code: crt.sh; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Osint Recon safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Osint Recon use?

Osint Recon is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Osint Recon use?

About 1.1k tokens (SKILL.md is roughly 4.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Osint Recon?

Skills that share tags, products or a category with Osint Recon: Metabigor OSINT Recon (j3ssie/metabigor, 1.9k stars), Ctf Osint (ljagiello/ctf-skills, 3.4k stars), ShadowBroker Intelligence Client (BigBodyCobain/Shadowbroker, 11k stars) and Awesome Osint Operator (shoyann/RZK-The-Hunter, 141 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Osint Recon?

briiirussell (a GitHub user) maintains it in briiirussell/cybersecurity-skills, which has 413 GitHub stars. The repository holds 25 skills in this directory. The repository was last updated on May 27, 2026.

Source: briiirussell/cybersecurity-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.