Agent skill

Unbroker

by CoWork-OS in CoWork-OS/CoWork-OS

Find and remove authorized personal information exposures from data brokers and people-search sites with a consent-gated local workflow.

MITAuto-check passedSecurity

Install Unbroker

skills CLI
$ npx skills add CoWork-OS/CoWork-OS --skill unbroker -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install CoWork-OS/CoWork-OS unbroker --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/CoWork-OS/CoWork-OS.git skills-src && mkdir -p .claude/skills && cp -r skills-src/resources/skills/unbroker .claude/skills/unbroker && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
unbroker
GitHub stars
477
Token cost
~2.9k tokens
SKILL.md length
1,377 words
Files
63 (incl. scripts, references, assets)
Skills in repo
46
Repo updated
First seen
Licence
MIT

At a glance

Find and remove authorized personal information exposures from data brokers and people-search sites with a consent-gated local workflow.

  • Works in 5 steps: Setup (once, no questions). Run $PDD… → Intake + consent (the ONE human… → Drain the queue. Loop → …
  • Tasks that involve OSINT
  • SKILL.md covers Autonomy contract, When to Use, Operational setup and Procedure (the autonomous loop), plus 2 more sections
  • Calls python3

What it does

Unbroker is an agent skill from CoWork-OS/CoWork-OS. Find and remove authorized personal information exposures from data brokers and people-search sites with a consent-gated local workflow.

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 65 other files, including scripts, reference files and assets (for example `README.md`, `references/brokers/addresses.json` and `references/brokers/advancedbackgroundchecks.json`).

It sits in Security, covering OSINT. The repository describes itself as: Local-first personal agentic OS and everything app for coding, knowledge work, web design, automations, and artifacts. The licence is MIT.

When your agent uses it

  • Tasks that involve OSINT

Example prompts

  • “/unbroker”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Setup (once, no questions). Run $PDD setup --auto - it detects capabilities and configures
  2. Intake + consent (the ONE human conversation). $PDD intake ... with --consent (and
  3. Drain the queue. Loop
  4. Scanning (when next says so). For fanout_scan: run $PDD fanout and **spawn one
  5. Opt-outs (when next says so). Actions come pre-ordered parents-first with steps from each

What it can do on your machine

Read from SKILL.md and the folder at commit 0ace02b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/, which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Unbroker loads about 2.9k tokens when it runs, and up to ~33k if it reads all its reference files. Until then it costs about 36 tokens; SKILL.md has 1,377 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~36
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~33k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from CoWork-OS/CoWork-OS at commit 0ace02b, republished under its MIT licence (© CoWork-OS). 1,377 words, ~2,906 tokens.

Download SKILL.mdSave it as .claude/skills/unbroker/SKILL.md (or your agent's skills folder). This skill also uses 62 other files; get the full folder from GitHub.
name
unbroker
description
Find and remove authorized personal information exposures from data brokers and people-search sites with a consent-gated local workflow.
version
1.0.0
metadata.author
CoWork OS Contributors <info@coworkosapp.com>
metadata.source-author
SHL0MS / Nous Research, ported by CoWork OS

unbroker

This CoWork OS bundled port is based on the upstream Hermes Agent unbroker skill: https://github.com/NousResearch/hermes-agent/tree/main/optional-skills/security/unbroker

CoWork runtime mapping:

  • Treat terminal as CoWork's shell/run_command capability.
  • Treat web_extract as CoWork web search, fetch, or extraction tools.
  • Treat browser_* as the available CoWork browser automation tools.
  • Treat delegate_task as CoWork multi-agent orchestration when available.
  • Treat cronjob as CoWork scheduling/automation.
  • The Python engine stores data under $PDD_DATA_DIR when set. Otherwise it prefers $COWORK_HOME/unbroker, then $COWORK_USER_DATA_DIR/unbroker, then the upstream legacy $HERMES_HOME/unbroker / ~/.hermes/unbroker path.

Code is MIT licensed. Broker data includes BADBOOL-derived data under CC BY-NC-SA 4.0; keep the license and attribution notes in LICENSE.txt and the README intact when redistributing.

Find where a person's personal information (name, addresses, phone, email, relatives) is exposed on data brokers and people-search sites, then remove it - automatically where possible, with guided human steps only where a site demands a CAPTCHA, government ID, phone call, or fax. Manages multiple people independently. It does not defeat anti-bot systems, does not act on anyone without recorded consent, and does not remove public records (voter/property/court) or accounts the person controls.

The Python CLI (scripts/pdd.py) owns the deterministic state - config, dossiers + consent, the broker database, tier planning, the ledger, drafts, reports, email sending (SMTP), verification-link polling (IMAP), and the autonomous action queue (next). You (the agent) do the scanning, form-driving, parallel work, and scheduling with the matching CoWork tools.

Autonomy contract

This skill is designed to run hands-off. After intake (+ recorded consent) there are exactly TWO legitimate human touchpoints: (1) the intake conversation itself, and (2) ONE consolidated human-task digest at the end of the run ($PDD tasks). Between those:

  • Never ask the operator to choose configuration. $PDD setup --auto detects capabilities and picks the most autonomous valid config itself.
  • Never pause before individual submissions when autonomy=full (the default): the consent recorded at intake is standing authorization for T0-T2 opt-outs. (autonomy=assisted restores per-submission confirmation for cautious operators - honor confirm_first flags in next output.)
  • Never interrupt the run for human-only work. Record it (record ... human_task_queued --reason "...") and keep going; it all surfaces once in the final digest.
  • Drive the whole run as a loop over $PDD next <subject> - it returns the exact ordered actions to take right now (scan, poll verification, re-check, opt out parents-first, requeue blocked), plus the human digest. Execute every action, record outcomes, re-run next, repeat until done_for_now. Then present the digest, report, and schedule the cron.

The hard limits that autonomy never overrides: no acting without recorded consent, no disclosure beyond disclosure_fields, no CAPTCHA/anti-bot bypass, and confirmed_removed only after a verifying re-scan.

When to Use

  • "Remove my (or my family member's) data from data brokers / people-search sites."
  • "Opt me out", "delete me from Spokeo/Whitepages/etc.", "clean up after a doxxing."
  • "Set up recurring privacy monitoring" (brokers re-list people).
  • Checking which brokers still expose someone and why.

Operational setup

Before running any command, read references/operations.md for prerequisites, safe command syntax, quick reference, batch sequencing, consent boundaries, and failure recovery. Never infer consent or submit removals outside the recorded scope.

Procedure (the autonomous loop)

  1. Setup (once, no questions). Run $PDD setup --auto - it detects capabilities and configures the most autonomous valid combination itself (programmatic email when EMAIL_* creds exist, Browserbase when its key exists, age encryption when the binary exists, autonomy=full). Then $PDD doctor and show the operator the readiness output for information, not as a question - proceed immediately. Mention what would unlock more automation (e.g. email creds) but do not wait.

  2. Intake + consent (the ONE human conversation). $PDD intake ... with --consent (and --consent-method). Without consent the engine refuses to plan or act. Collect everything in one pass - names/aliases, current + prior cities, emails, phones - so you never have to come back with questions. For California subjects, also read references/legal/drop.md: next will surface a drop_submit one-shot that deletes from every registered broker (~545) at once, which is the single highest-leverage action. File it, then drop <subject> --filed. For non-CA subjects the registry is covered by targeted CCPA/GDPR emails (registry --search, then send-email); the people-search sites are worked directly in either case.

  3. Drain the queue. Loop:

    while true:
      q = $PDD next <subject>
      if q.actions is empty: break
      execute EVERY action in order; record each outcome via $PDD record

    next emits, in order: refresh_brokers (stale cache), fanout_scan/scan_inline (Phase 1 crawl - see step 4), poll_verification (in-flight email confirmations), verify_removal (due re-checks), optout_web_form/optout_email_send (Phase 2, parents-first with playbook steps), indirect_email_send, and stealth_rescan. Human-only work never appears as an action - it accumulates in q.human_digest. In autonomy=full, execute actions without pausing; honor confirm_first in assisted mode.

  4. Scanning (when next says so). For fanout_scan: run $PDD fanout <subject> and spawn one CoWork subagent per batch, in parallel when multi-agent tools are available, passing that batch's ready-made brief - do not scan all brokers yourself sequentially. For scan_inline: scan the few brokers yourself. Either way, each broker gets every search_vectors entry via the references/methods.md ladder (web extraction -> site: probe -> browser automation -> stealth-capable browser/scraping), a 404 is INCONCLUSIVE (not not_found), blocked is recorded when antibot is set and no stealth browser is available, and subject vs namesake/relative is confirmed before recording: $PDD record <subject> <broker> <found|not_found|indirect_exposure|blocked> --found <bool> --evidence '{"listing_urls":[...]}'. The parent re-verifies key found claims from subagents before trusting them.

  5. Opt-outs (when next says so). Actions come pre-ordered parents-first with steps from each broker record's own optout.playbook (field-verified; cluster parents like PeopleConnect, Whitepages, BeenVerified, Spokeo have exact, live-checked recipes). Deletion usually beats suppression: when an action carries prefer_deletion, complete the record's DELETION lane, not just the hide-my-listing flow. When it carries prefer_suppression instead (PeopleConnect - deleting removes your suppressions and does not stop re-listing), do the suppression flow and keep it maintained; use their Delete button only for a deliberate data-purge. Per method:

    • web_form → drive optout_url with browser_navigate/browser_type/browser_click, submit only disclosure_fields, screenshot the confirmation, then the action's after record command. Playbooks may end with a right-to-delete send-email follow-up - do it (full erasure, not just listing suppression).
    • email → $PDD send-email <subject> <broker> --kind <ccpa|gdpr|generic> --to <addr> --listing <url> records + discloses in one step (recipient locked to addresses the broker record declares; next picks the kind from residency - never claim CCPA/GDPR for someone who can't). In browser mode it returns a recipient-locked compose payload: compose a new message to compose.to with compose.subject/compose.body exactly in the operator's webmail via CoWork browser tools and send (no password); in programmatic mode it SMTP-sends. next also routes human-gated forms (phone-callback/gov-ID) through a broker's deletion email when one exists - the rescue lane (verified Whitepages pattern). Draft-only falls back to render-email + a digest entry.
    • captcha → soft/managed challenges clear automatically on the default cloud browser (proceed as normal); only a hard interactive/behavioral challenge it can't pass is recorded blocked (requeued for the stealth/operator-browser pass). Never a solver service.
    • phone_callback / account / gov_id / fax / mail / voice (T3) without a deletion email → never an agent action; next already routed these to the digest. Record them: $PDD record <subject> <broker> human_task_queued --reason "...".
  6. Verification (when next says so). In programmatic mode $PDD poll-verification <subject> finds arrived confirmation links via IMAP (anti-phishing scored, auto-advances state). In browser mode, open the broker's confirmation email in the operator's webmail and run $PDD verify-link <subject> <broker> --text '<body>' to score the link. Either way open the link in the same browser (several brokers bind the verification session to the browser that opens it), finish the flow, then record awaiting_processing. confirmed_removed ONLY after a verifying re-scan shows the listing gone - never off the submission flow's own confirmation page.

  7. Wrap up (once per run). When next returns no actions: present $PDD tasks <subject> (the consolidated human digest) if non-empty, then $PDD status <subject>; if the Sheets tracker is on, append $PDD report <subject> --sheets rows via CoWork's Google Sheets/Workspace capability.

  8. Schedule the next wake-up. next returns next_wake_at (earliest due re-check). Create ONE CoWork scheduled automation that re-runs this skill's loop for the subject (a prompt like: "run the unbroker loop for <subject_id>: $PDD next and execute all actions"). Processing windows, verification polls, and reappearance sweeps all flow through the same queue, so the case keeps advancing with zero human attention.

Show full SKILL.md (65 more words)Show less

Pitfalls

Apply the safety and recovery rules in references/operations.md, especially around CAPTCHA, verification links, duplicate submissions, rate limits, and evidence capture.

Verification

  • scripts/run_tests.sh tests/skills/test_unbroker_skill.py (hermetic; no network), or the dependency-free runner python3 tests/skills/test_unbroker_skill.py.
  • Dry run: $PDD setup --auto && $PDD doctor && SID=$($PDD intake --full-name "Test Person" --email t@example.com --consent | python3 -c 'import sys,json;print(json.load(sys.stdin)["subject_id"])') && $PDD next "$SID" and confirm a readiness summary plus an ordered action queue.

© CoWork-OS, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 62 other files (scripts, references, assets) in resources/skills/unbroker of CoWork-OS/CoWork-OS.

  • SKILL.md
  • LICENSE.txt
  • README.md
  • assets/unbroker.png
  • references/brokers/addresses.json
  • references/brokers/advancedbackgroundchecks.json
  • references/brokers/beenverified.json
  • references/brokers/clustal.json
  • references/brokers/clustrmaps.json
  • references/brokers/cyberbackgroundchecks.json
  • references/brokers/familytreenow.json
  • references/brokers/fastpeoplesearch.json
  • references/brokers/intelius.json
  • references/brokers/mylife.json
  • references/brokers/nuwber.json
  • references/brokers/peekyou.json
  • references/brokers/peoplefinders.json
  • references/brokers/radaris.json
  • … and 45 more

Open the folder on GitHubat commit 0ace02b

Compare with similar skills

Unbroker next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Unbroker compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Unbroker this skillCoWork-OS/CoWork-OS477—~2.9kAutomated safety check: PassMIT
Checkpointautomateyournetwork/netclaw676—~2.3kAutomated safety check: NotesApache-2.0
Metabigor OSINT Reconj3ssie/metabigor1.9k—~2.4kAutomated safety check: PassMIT
Ctf Osintljagiello/ctf-skills3.4k1 repos~2.3kAutomated safety check: NotesMIT
ShadowBroker Intelligence ClientBigBodyCobain/Shadowbroker11k—~8.9kAutomated safety check: WarnAGPL-3.0
Awesome Osint Operatorshoyann/RZK-The-Hunter141—~4.8kAutomated safety check: PassCC-BY-SA-4.0

Similar skills

  • Checkpoint

    automateyournetwork/netclaw

    Inspect Check Point security policies, threat intelligence, gateways, and SASE through its MCP integrations.

    676 GitHub stars~2.3k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Metabigor OSINT Recon

    j3ssie/metabigor

    Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys.

    1.9k GitHub stars~2.4k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Ctf Osint

    ljagiello/ctf-skills

    Provides open source intelligence techniques for CTF challenges.

    3.4k GitHub starsUsed in 1 repo~2.3k tokens
    SecurityAuto-check: notes
  • ShadowBroker Intelligence Client

    BigBodyCobain/Shadowbroker

    Lets an agent query a ShadowBroker OSINT platform for tracked flights, ships, satellites and news, and place its findings on the map as intel pins.

    11k GitHub stars~8.9k tokensUpdated today
    SecurityAuto-check: warnings
  • Awesome Osint Operator

    shoyann/RZK-The-Hunter

    Ethical, evidence-first OSINT planning, tool selection, verification, monitoring, reporting, and guarded official wanted/fugitive-person location intelligence using a structured catalog adapted from…

    141 GitHub stars~4.8k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Run Claude Osint

    elementalsouls/Claude-OSINT

    Build, validate, and run the claude-osint skills repo — check SKILL.md frontmatter, run the secretscan.py and h1reference.py helpers, run sync-skill-content.sh, run the smoke test.

    2.8k GitHub stars~1.2k tokensUpdated yesterday
    SecurityAuto-check passed

More from CoWork-OS/CoWork-OS

All 46 skills in this repo
  • Calendly

    CoWork-OS/CoWork-OS

    Manage Calendly scheduling via the v2 API. An agent skill from CoWork-OS/CoWork-OS.

    480 GitHub stars~595 tokensUpdated today
    Auto-check passed
  • Humanizer

    CoWork-OS/CoWork-OS

    Rewrite AI-generated text to sound natural and human-written.

    480 GitHub stars~557 tokensUpdated today
    Auto-check passed
  • Marketing Strategist

    CoWork-OS/CoWork-OS

    Comprehensive marketing strategy across 25 disciplines — positioning, copywriting frameworks, buyer psychology, SEO, CRO, paid ads, funnel architecture, content strategy, growth loops, analytics…

    480 GitHub stars~893 tokensUpdated today
    Auto-check passed
  • Moltbook

    CoWork-OS/CoWork-OS

    Interact with Moltbook — the social network for AI agents. An agent skill from CoWork-OS/CoWork-OS.

    480 GitHub stars~579 tokensUpdated today
    Auto-check passed
  • Polymarket

    CoWork-OS/CoWork-OS

    Query Polymarket prediction markets — search events, check odds and prices, view trending markets, track price momentum, get orderbook depth, analyze volume, and monitor market resolution timelines.

    480 GitHub stars~616 tokensUpdated today
    Auto-check passed
  • Skill Creator

    CoWork-OS/CoWork-OS

    Create or update AgentSkills for CoWork-OSS. An agent skill from CoWork-OS/CoWork-OS.

    480 GitHub stars~493 tokensUpdated today
    Auto-check passed

Questions about Unbroker

What does Unbroker do?

Find and remove authorized personal information exposures from data brokers and people-search sites with a consent-gated local workflow. Unbroker is an agent skill from CoWork-OS/CoWork-OS. Find and remove authorized personal information exposures from data brokers and people-search sites with a consent-gated local workflow.

When should I use Unbroker?

Unbroker fits situations like: tasks that involve OSINT.

How do I install Unbroker in Claude Code?

Run `npx skills add CoWork-OS/CoWork-OS --skill unbroker -a claude-code`. Or copy the skill folder (resources/skills/unbroker in CoWork-OS/CoWork-OS) into .claude/skills/unbroker in your project. Claude Code loads it when a task matches its description.

How do I install Unbroker in Codex?

Run `npx skills add CoWork-OS/CoWork-OS --skill unbroker -a codex`. Or copy the skill folder (resources/skills/unbroker in CoWork-OS/CoWork-OS) into .agents/skills/unbroker in your project. Codex loads it when a task matches its description.

Can I use Unbroker in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add CoWork-OS/CoWork-OS --skill unbroker -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/unbroker, .gemini/skills/unbroker, .github/skills/unbroker and .opencode/skills/unbroker in your project.

What does Unbroker need to run?

Going by SKILL.md and its folder, Unbroker needs the command-line tools its instructions call (python3). Our summary lists: Python 3.

Does Unbroker access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Unbroker safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Unbroker use?

Unbroker is published under the MIT licence (from the LICENSE file in the skill folder). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Unbroker use?

About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 30k tokens, read only when the agent opens those files.

What are the alternatives to Unbroker?

Skills that share tags, products or a category with Unbroker: Checkpoint (automateyournetwork/netclaw, 676 stars), Metabigor OSINT Recon (j3ssie/metabigor, 1.9k stars), Ctf Osint (ljagiello/ctf-skills, 3.4k stars) and ShadowBroker Intelligence Client (BigBodyCobain/Shadowbroker, 11k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Unbroker?

CoWork-OS (a GitHub organization) maintains it in CoWork-OS/CoWork-OS, which has 477 GitHub stars. The repository holds 46 skills in this directory. The repository was last updated on October 9, 2026.

Source: CoWork-OS/CoWork-OS on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.