Metabigor OSINT Recon
j3ssie/metabigor
Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys.
Triage ASM/recon output for ownership before testing — separate the target's real assets from namespace-collision noise.
$ npx skills add elementalsouls/Claude-BugHunter --skill recon-scope-triage -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install elementalsouls/Claude-BugHunter recon-scope-triage --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/elementalsouls/Claude-BugHunter.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/recon-scope-triage .claude/skills/recon-scope-triage && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "recon-scope-triage" agent skill from https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/recon-scope-triage into .claude/skills/recon-scope-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "recon-scope-triage", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/recon-scope-triageType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add elementalsouls/Claude-BugHunter --skill recon-scope-triage -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install elementalsouls/Claude-BugHunter recon-scope-triage --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elementalsouls/Claude-BugHunter.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/recon-scope-triage .agents/skills/recon-scope-triage && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "recon-scope-triage" agent skill from https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/recon-scope-triage into .agents/skills/recon-scope-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "recon-scope-triage", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add elementalsouls/Claude-BugHunter --skill recon-scope-triage -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install elementalsouls/Claude-BugHunter recon-scope-triage --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elementalsouls/Claude-BugHunter.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/recon-scope-triage .cursor/skills/recon-scope-triage && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "recon-scope-triage" agent skill from https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/recon-scope-triage into .cursor/skills/recon-scope-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "recon-scope-triage", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/elementalsouls/Claude-BugHunter.git --path skills/recon-scope-triage--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add elementalsouls/Claude-BugHunter --skill recon-scope-triage -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install elementalsouls/Claude-BugHunter recon-scope-triage --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elementalsouls/Claude-BugHunter.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/recon-scope-triage .gemini/skills/recon-scope-triage && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "recon-scope-triage" agent skill from https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/recon-scope-triage into .gemini/skills/recon-scope-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "recon-scope-triage", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install elementalsouls/Claude-BugHunter recon-scope-triageInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add elementalsouls/Claude-BugHunter --skill recon-scope-triage -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/elementalsouls/Claude-BugHunter.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/recon-scope-triage .github/skills/recon-scope-triage && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "recon-scope-triage" agent skill from https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/recon-scope-triage into .github/skills/recon-scope-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "recon-scope-triage", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add elementalsouls/Claude-BugHunter --skill recon-scope-triage -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install elementalsouls/Claude-BugHunter recon-scope-triage --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elementalsouls/Claude-BugHunter.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/recon-scope-triage .opencode/skills/recon-scope-triage && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "recon-scope-triage" agent skill from https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/recon-scope-triage into .opencode/skills/recon-scope-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "recon-scope-triage", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
recon-scope-triageTriage ASM/recon output for ownership before testing — separate the target's real assets from namespace-collision noise.
Recon Scope Triage is an agent skill from elementalsouls/Claude-BugHunter. Triage ASM/recon output for ownership before testing — separate the target's real assets from namespace-collision noise. Automated recon keyword-matches on the brand name, so for any target whose name is a common/dictionary word, the output is dominated by assets belonging to UNRELATED same-named companies (repos, cloud buckets, mobile apps, breach corpora, typosquats). Built from an authorized engagement where an ASM report's "Criticals" were overwhelmingly false positives and the combo/repos/mobile/bucket lists…
Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Bug bounty and OSINT. The repository describes itself as: A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patterns curated across 24 core vulnerability classes… The licence is MIT.
2 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit ec51cd4. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
curlphpFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use curl, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Recon Scope Triage loads about 1.9k tokens when it runs. Until then it costs about 175 tokens; SKILL.md has 811 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
Automated `.env` / `.git` / `actuator` / admin-panel "Criticals" are overwhelmingly **soft-404s**: SPA/framework catch-aize_download}\n" https://host.target.com/.envtch-all (`.git/config` starts `[core]`; `.env` has `KEY=value`; phpinfo has the XHTML-transitional doctype + `PHP VersioAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from elementalsouls/Claude-BugHunter at commit ec51cd4, republished under its MIT licence (© elementalsouls). 811 words, ~1,867 tokens.
.claude/skills/recon-scope-triage/SKILL.md (or your agent's skills folder).Trigger when:
apex, summit, vertex, nova, core, orbit, pulse, unity…)The two failure modes this skill prevents:
Rule: ownership is guilty-until-proven. An asset is the target's only when a concrete ownership signal ties it to the target — never because a scanner's keyword matched.
| Recon source | How it collides | Verify ownership by |
|---|---|---|
| GitHub repos | Search matched the brand word in repo name / topic / a string | Repo owner is the org's GH org; commits from org emails; code references the org's real domains/infra. A repo named <word>-backend by a random user = noise. |
| Cloud buckets (S3/GCS) | Bucket names are a global namespace; <word>-static, <word>-data, <word>-public exist for someone | Bucket content references the target; bucket name correlates with a confirmed target subdomain (x.target.com ↔ x-public) AND content matches; ACL/owner metadata. Generic content (other-language, other-industry) = not theirs. |
| Mobile apps | Store search matched the brand word in app name / package | Publisher account = the org; package reverse-DNS = an owned domain (com.<owneddomain>.app); dev cert; app calls owned API hosts. Mature ASM tools emit an "apps_accepted=0" / ownership-confidence field — read it. |
| Breach corpora / combos | Email local-or-domain contains the brand word | Exact owned-domain match only (@target.com), not @<word>group.com / @something<word>.com. A different domain that contains the word is a different org. |
| Typosquats | Generated permutations of the name | These are defensive/brand-protection findings, not offensive scope — note and move on. |
| Stack/forum/paste hits | Brand word in body | Body references the target's real domain/subdomain/employee/secret. Ownership-confidence < threshold = drop. |
Automated .env / .git / actuator / admin-panel "Criticals" are overwhelmingly soft-404s: SPA/framework catch-alls returning HTTP 200 (or 403) for every path. Verify EACH before believing it:
# the "finding"
curl -s -o /tmp/a -w "%{http_code} %{size_download}\n" https://host.target.com/.env
# a junk control on the same host
curl -s -o /tmp/b -w "%{http_code} %{size_download}\n" https://host.target.com/zzz-nonsense-$RANDOM
# identical byte length / body → FALSE POSITIVE (catch-all), discard
cmp -s /tmp/a /tmp/b && echo "SOFT-404 false positive" || echo "differs — investigate"Real exposures have a content-type + signature that differs from the catch-all (.git/config starts [core]; .env has KEY=value; phpinfo has the XHTML-transitional doctype + PHP Version). A physical .php/phpinfo.php that returns a bigger/different body than the junk control is the real-vs-soft-404 tell.
loot/quarantined_<source>.txt) so it's auditable that you saw them and chose not to target them.user@<word>company.com is a different company's employee.For a target whose brand is a common word, expect the bulk of automated "owned" assets to be collisions:
<word>group.com, <region><word>.com).On a real engagement against a dictionary-word brand, after clearing this noise the only genuinely-owned high-severity finding was discoverable solely by manual tradecraft (a JS-bundle → API discovery, see hunt-spa-api) — it was nowhere in the hundreds of scanner "Criticals." Triage-first is what made the engagement productive instead of a goose chase.
triage-validation — asset-ownership triage (this skill) precedes finding-validity triage (the 7-Question Gate). Ownership first, then validity.redteam-mindset — "aggressive default" means probe every owned live surface; this skill defines which surfaces are owned so persistence isn't wasted on collisions.hunt-spa-api — once an API host passes ownership triage, this is how you test it.offensive-osint / osint-methodology — feed ownership anchors (verified domains, tenant brand, dev accounts) from OSINT into this triage.© elementalsouls, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/recon-scope-triage of elementalsouls/Claude-BugHunter.
Open the folder on GitHubat commit ec51cd4
Recon Scope Triage next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Recon Scope Triage this skillelementalsouls/Claude-BugHunter | 4.8k | — | ~1.9k | Automated safety check: Notes | MIT | |
| Metabigor OSINT Reconj3ssie/metabigor | 1.8k | — | ~2.4k | Automated safety check: Pass | MIT | |
| Osint Methodologyelementalsouls/Claude-OSINT | 2.8k | — | ~8.7k | Automated safety check: Notes | MIT | |
| External Recon PlaybookPentesterFlow/agent | 1.4k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | |
| Web3 Smart Contract Auditawarexone/Agentic-Bug-Hunter | 5.3k | 3 repos | ~4.5k | Automated safety check: Pass | MIT | |
| Bug Bounty Hunting Methodologyawarexone/Agentic-Bug-Hunter | 5.3k | 2 repos | ~4.7k | Automated safety check: Pass | MIT |
j3ssie/metabigor
Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys.
elementalsouls/Claude-OSINT
Comprehensive OSINT methodology for external red-team operations and authorized attack-surface assessments.
PentesterFlow/agent
Maps the attack surface of a web domain you are authorized to test: confirms scope, lists subdomains from public sources, probes live hosts and fingerprints technology.
awarexone/Agentic-Bug-Hunter
Guides smart contract audits and bounty target selection with ten DeFi bug classes, kill signals, a Foundry PoC template and grep patterns.
awarexone/Agentic-Bug-Hunter
Orchestrates a bug bounty session with a 5-phase workflow and a critical-thinking framework covering developer psychology, anomaly detection and What-If experiments.
tanweai/wooyun-legacy
WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…
elementalsouls/Claude-BugHunter
Hunting skill for business logic vulnerabilities. An agent skill from elementalsouls/Claude-BugHunter.
elementalsouls/Claude-BugHunter
Hunt API security misconfiguration — mass assignment, prototype pollution, HTTP verb tampering.
elementalsouls/Claude-BugHunter
Hunt account takeover taxonomy — 9 distinct paths to ATO, plus chains.
elementalsouls/Claude-BugHunter
Hunt fintech-specific GraphQL vulnerabilities: money-movement mutations (transfers, redemptions, withdrawals, card top-ups), ledger/balance/portfolio query IDOR, decimal-precision and rounding…
elementalsouls/Claude-BugHunter
Hunt HTTP request smuggling (CL.TE, TE.CL, H2.CL, H2.TE). An agent skill from elementalsouls/Claude-BugHunter.
elementalsouls/Claude-BugHunter
Hunt JWT cryptographic failures — alg:none signature-stripping and RS256→HS256 key-confusion that let an attacker forge a token for any identity (e.g.
Categories
Triage ASM/recon output for ownership before testing — separate the target's real assets from namespace-collision noise. Recon Scope Triage is an agent skill from elementalsouls/Claude-BugHunter. Triage ASM/recon output for ownership before testing — separate the target's real assets from namespace-collision noise.
Recon Scope Triage fits situations like: tasks that involve Bug bounty; tasks that involve OSINT.
Run `npx skills add elementalsouls/Claude-BugHunter --skill recon-scope-triage -a claude-code`. Or copy the skill folder (skills/recon-scope-triage in elementalsouls/Claude-BugHunter) into .claude/skills/recon-scope-triage in your project. Claude Code loads it when a task matches its description.
Run `npx skills add elementalsouls/Claude-BugHunter --skill recon-scope-triage -a codex`. Or copy the skill folder (skills/recon-scope-triage in elementalsouls/Claude-BugHunter) into .agents/skills/recon-scope-triage in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add elementalsouls/Claude-BugHunter --skill recon-scope-triage -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/recon-scope-triage, .gemini/skills/recon-scope-triage, .github/skills/recon-scope-triage and .opencode/skills/recon-scope-triage in your project.
Going by SKILL.md and its folder, Recon Scope Triage needs the command-line tools its instructions call (curl and php).
SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Recon Scope Triage is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.9k tokens (SKILL.md is roughly 7.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Recon Scope Triage: Metabigor OSINT Recon (j3ssie/metabigor, 1.8k stars), Osint Methodology (elementalsouls/Claude-OSINT, 2.8k stars), External Recon Playbook (PentesterFlow/agent, 1.4k stars) and Web3 Smart Contract Audit (awarexone/Agentic-Bug-Hunter, 5.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
elementalsouls (a GitHub user) maintains it in elementalsouls/Claude-BugHunter, which has 4,816 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on October 8, 2026.
Source: elementalsouls/Claude-BugHunter on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.