Osint Methodology
elementalsouls/Claude-OSINT
Comprehensive OSINT methodology for external red-team operations and authorized attack-surface assessments.
Plans and runs authorized reconnaissance to enumerate a target's external attack surface (DNS, subdomains, ports, web tech) and produces a prioritized report.
$ npx skills add criptogus/agent-evolve-network --skill recon-attack-surface -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install criptogus/agent-evolve-network recon-attack-surface --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/criptogus/agent-evolve-network.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/recon-attack-surface .claude/skills/recon-attack-surface && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "recon-attack-surface" agent skill from https://github.com/criptogus/agent-evolve-network/tree/main/skills/recon-attack-surface into .claude/skills/recon-attack-surface/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "recon-attack-surface", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/criptogus/agent-evolve-network/tree/main/skills/recon-attack-surfaceType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add criptogus/agent-evolve-network --skill recon-attack-surface -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install criptogus/agent-evolve-network recon-attack-surface --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/criptogus/agent-evolve-network.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/recon-attack-surface .agents/skills/recon-attack-surface && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "recon-attack-surface" agent skill from https://github.com/criptogus/agent-evolve-network/tree/main/skills/recon-attack-surface into .agents/skills/recon-attack-surface/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "recon-attack-surface", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add criptogus/agent-evolve-network --skill recon-attack-surface -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install criptogus/agent-evolve-network recon-attack-surface --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/criptogus/agent-evolve-network.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/recon-attack-surface .cursor/skills/recon-attack-surface && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "recon-attack-surface" agent skill from https://github.com/criptogus/agent-evolve-network/tree/main/skills/recon-attack-surface into .cursor/skills/recon-attack-surface/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "recon-attack-surface", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/criptogus/agent-evolve-network.git --path skills/recon-attack-surface--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add criptogus/agent-evolve-network --skill recon-attack-surface -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install criptogus/agent-evolve-network recon-attack-surface --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/criptogus/agent-evolve-network.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/recon-attack-surface .gemini/skills/recon-attack-surface && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "recon-attack-surface" agent skill from https://github.com/criptogus/agent-evolve-network/tree/main/skills/recon-attack-surface into .gemini/skills/recon-attack-surface/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "recon-attack-surface", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install criptogus/agent-evolve-network recon-attack-surfaceInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add criptogus/agent-evolve-network --skill recon-attack-surface -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/criptogus/agent-evolve-network.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/recon-attack-surface .github/skills/recon-attack-surface && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "recon-attack-surface" agent skill from https://github.com/criptogus/agent-evolve-network/tree/main/skills/recon-attack-surface into .github/skills/recon-attack-surface/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "recon-attack-surface", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add criptogus/agent-evolve-network --skill recon-attack-surface -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install criptogus/agent-evolve-network recon-attack-surface --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/criptogus/agent-evolve-network.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/recon-attack-surface .opencode/skills/recon-attack-surface && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "recon-attack-surface" agent skill from https://github.com/criptogus/agent-evolve-network/tree/main/skills/recon-attack-surface into .opencode/skills/recon-attack-surface/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "recon-attack-surface", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
recon-attack-surfacePlans and runs authorized reconnaissance to enumerate a target's external attack surface (DNS, subdomains, ports, web tech) and produces a prioritized report.
Recon Attack Surface is an agent skill from criptogus/agent-evolve-network. Plans and runs authorized reconnaissance to enumerate a target's external attack surface (DNS, subdomains, ports, web tech) and produces a prioritized report. Use when the user asks for recon & attack surface mapper work, or mentions recon, attack, surface.
Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Threat modeling and Bug bounty. The licence is CC-BY-SA-4.0.
Read from SKILL.md and the folder at commit d19b920. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npxFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
superagentskill.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Recon Attack Surface loads about 1.2k tokens when it runs. Until then it costs about 70 tokens; SKILL.md has 246 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from criptogus/agent-evolve-network at commit d19b920, republished under its CC-BY-SA-4.0 licence (© criptogus). 246 words, ~1,156 tokens.
.claude/skills/recon-attack-surface/SKILL.md (or your agent's skills folder).Use for authorized pentests, bug-bounty programs and CTFs where the engagement scope clearly permits active probing. Builds a structured plan, suggests safe command sequences (subfinder/amass, dnsx, naabu, httpx, nuclei) and turns raw output into a ranked attack-surface map. Do NOT use against assets the operator has not been authorized to test.
You are an authorized red-team analyst. Before producing any commands, restate the in-scope assets and assumed authorization in one paragraph. If scope is missing or unclear, ask for it and stop. Then produce: (1) a passive recon plan (no traffic to target), (2) an active recon plan with rate-limit and noise notes, (3) a prioritized findings table (asset, signal, risk, next step). Never fabricate scan output. Never output exploit payloads or post-exploitation steps in this skill.
Input:
{
"type": "object",
"properties": {
"target": {
"type": "string",
"description": "root domain, IP range or org name"
},
"scope": {
"type": "string",
"description": "explicit in-scope assets and rules of engagement"
},
"authorization": {
"type": "string",
"description": "who authorized the test and when"
}
},
"required": [
"target",
"scope",
"authorization"
]
}Output:
{
"type": "object",
"properties": {
"plan_markdown": {
"type": "string"
},
"findings_table": {
"type": "array"
}
},
"required": [
"plan_markdown"
]
}Input:
target: example.com
scope: "*.example.com, no .gov subdomains, no DoS, max 10 rps"
authorization: "HackerOne program, signed brief 2026-04-12"Expected output:
## Authorization recap
Authorized via HackerOne brief dated 2026-04-12. In scope: *.example.com excluding .gov subdomains. Rate cap: 10 rps. No DoS.
## Passive recon
- crt.sh + Subfinder for subdomain discovery
- PassiveTotal / SecurityTrails lookups
## Active recon (≤10 rps)
- dnsx resolution sweep, then naabu top-1000 ports, then httpx fingerprint
## Prioritized findings
| Asset | Signal | Risk | Next step |Input:
target: 10.20.0.0/16
scope: "Internal corporate network excluding 10.20.99.0/24 (legal). No exploitation, max 50 pps."
authorization: "Signed SOW with Acme Corp, engagement window 2026-05-13 to 2026-05-17"Expected output:
## Authorization recap
Authorized via signed SOW dated 2026-05-13. Scope: 10.20.0.0/16 minus 10.20.99.0/24. Rate cap: 50 pps. No exploitation; recon and fingerprint only.
## Passive recon
- DHCP / DNS audit from provided collection files
- Pull CMDB / asset inventory if available
## Active recon (≤50 pps)
- `nmap -sn -T2 --max-rate 50 10.20.0.0/16` for liveness
- `naabu -rate 50 -top-ports 100` against live hosts
- `httpx -silent -title -tech-detect` against web ports
## Prioritized findings
| Asset | Signal | Risk | Next step |
| 10.20.4.17 | Exposed `:445` SMBv1 banner | High | Verify CVE-2017-0144 patch level via patch records |
| 10.20.7.10 | Default Tomcat /manager page | Medium | Confirm credentials are not default; document |This skill is graded on the Super Agent Skill network: format, substance and adversarial (prompt-injection) testing produce a public Trust Score.
Reinstall or update with npx skills update, or pull the live graded version with
npx super-agent install recon-attack-surface.
© criptogus, CC-BY-SA-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/recon-attack-surface of criptogus/agent-evolve-network.
Open the folder on GitHubat commit d19b920
Recon Attack Surface next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Recon Attack Surface this skillcriptogus/agent-evolve-network | 288 | — | ~1.2k | Automated safety check: Pass | CC-BY-SA-4.0 | |
| Osint Methodologyelementalsouls/Claude-OSINT | 2.8k | — | ~8.7k | Automated safety check: Notes | MIT | |
| Security Specialistfabricioctelles/skills | 106 | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | |
| Web2 Reconawarexone/Agentic-Bug-Hunter | 5.3k | 2 repos | ~6.4k | Automated safety check: Warn | MIT | |
| Audit Context Buildingtrailofbits/skills | 7.4k | — | ~996 | Automated safety check: Pass | CC-BY-SA-4.0 | |
| Reconbriiirussell/cybersecurity-skills | 413 | — | ~1.1k | Automated safety check: Notes | MIT |
elementalsouls/Claude-OSINT
Comprehensive OSINT methodology for external red-team operations and authorized attack-surface assessments.
fabricioctelles/skills
Runs security audits on codebases — full scans, diff reviews, threat models, vulnerability triage, remediation guidance, and finding tracking.
awarexone/Agentic-Bug-Hunter
Web2 recon pipeline — subdomain enumeration (subfinder, Chaos API, assetfinder), live host discovery (dnsx, httpx), URL crawling (katana, waybackurls, gau), directory fuzzing (ffuf), JS analysis…
trailofbits/skills
Understand a codebase before looking for bugs in it - what each function assumes, what it guarantees, and what it depends on elsewhere.
briiirussell/cybersecurity-skills
Perform structured reconnaissance and attack surface enumeration for authorized penetration tests, CTF challenges, and bug bounty programs.
transilienceai/communitytools
Domain assessment and web application mapping - subdomain discovery, port scanning, endpoint enumeration, API discovery, and attack surface analysis.
criptogus/agent-evolve-network
Kickoff research for a brand you haven't worked on before — web research, existing-ad analysis from the Meta Ad Library, editorial-grammar profiling, sourced + AI-generated brand assets, hook/CTA…
criptogus/agent-evolve-network
Produce a 9:16 social-native ad recreating the iPhone Apple Notes typing experience — the note begins with 1–2 visible lines, then progressively types additional paragraphs character-by-character…
criptogus/agent-evolve-network
Produce a 9:16 social-native ad that recreates a ChatGPT mobile chat — user types in the composer with the iOS keyboard visible, taps send, keyboard slides down, header right-cluster swaps…
criptogus/agent-evolve-network
Produce a 9:16 social-native ad that recreates an iMessage conversation reveal — bubbles pop in over time, composer types char-by-char, real Apple iMessage SFX hit on every send/receive, music bed…
criptogus/agent-evolve-network
Audits AWS, GCP and Azure environments (and matching IaC) for excessive permissions, public exposure, weak encryption defaults and missing logging.
criptogus/agent-evolve-network
Builds and debugs Cloudflare Workers, Durable Objects, KV, R2, D1, and Queues with edge-correct patterns.
Categories
Plans and runs authorized reconnaissance to enumerate a target's external attack surface (DNS, subdomains, ports, web tech) and produces a prioritized report. Recon Attack Surface is an agent skill from criptogus/agent-evolve-network. Plans and runs authorized reconnaissance to enumerate a target's external attack surface (DNS, subdomains, ports, web tech) and produces a prioritized report.
Recon Attack Surface fits situations like: the user asks for recon & attack surface mapper work; tasks that involve Threat modeling; tasks that involve Bug bounty.
Run `npx skills add criptogus/agent-evolve-network --skill recon-attack-surface -a claude-code`. Or copy the skill folder (skills/recon-attack-surface in criptogus/agent-evolve-network) into .claude/skills/recon-attack-surface in your project. Claude Code loads it when a task matches its description.
Run `npx skills add criptogus/agent-evolve-network --skill recon-attack-surface -a codex`. Or copy the skill folder (skills/recon-attack-surface in criptogus/agent-evolve-network) into .agents/skills/recon-attack-surface in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add criptogus/agent-evolve-network --skill recon-attack-surface -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/recon-attack-surface, .gemini/skills/recon-attack-surface, .github/skills/recon-attack-surface and .opencode/skills/recon-attack-surface in your project.
Going by SKILL.md and its folder, Recon Attack Surface needs the command-line tools its instructions call (npx). Our summary lists: Node.js.
SKILL.md names 1 domain. As links in the text: superagentskill.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Recon Attack Surface is published under the CC-BY-SA-4.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.2k tokens (SKILL.md is roughly 4.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Recon Attack Surface: Osint Methodology (elementalsouls/Claude-OSINT, 2.8k stars), Security Specialist (fabricioctelles/skills, 106 stars), Web2 Recon (awarexone/Agentic-Bug-Hunter, 5.3k stars) and Audit Context Building (trailofbits/skills, 7.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
criptogus (a GitHub user) maintains it in criptogus/agent-evolve-network, which has 288 GitHub stars. The repository holds 107 skills in this directory. The repository was last updated on September 9, 2026.
Source: criptogus/agent-evolve-network on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.