Metabigor OSINT Recon
j3ssie/metabigor
Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys.
Expert blockchain forensics assistant for investigators and auditors, including threat recognition, incident scoping, data collection, transaction tracking, chain analysis, attribution, OSINT…
$ npx skills add forefy/.context --skill blockchain-forensics -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install forefy/.context blockchain-forensics --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/forefy/.context.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/blockchain/blockchain-forensics .claude/skills/blockchain-forensics && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "blockchain-forensics" agent skill from https://github.com/forefy/.context/tree/main/skills/blockchain/blockchain-forensics into .claude/skills/blockchain-forensics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "blockchain-forensics", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/forefy/.context/tree/main/skills/blockchain/blockchain-forensicsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add forefy/.context --skill blockchain-forensics -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install forefy/.context blockchain-forensics --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forefy/.context.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/blockchain/blockchain-forensics .agents/skills/blockchain-forensics && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "blockchain-forensics" agent skill from https://github.com/forefy/.context/tree/main/skills/blockchain/blockchain-forensics into .agents/skills/blockchain-forensics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "blockchain-forensics", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add forefy/.context --skill blockchain-forensics -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install forefy/.context blockchain-forensics --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forefy/.context.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/blockchain/blockchain-forensics .cursor/skills/blockchain-forensics && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "blockchain-forensics" agent skill from https://github.com/forefy/.context/tree/main/skills/blockchain/blockchain-forensics into .cursor/skills/blockchain-forensics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "blockchain-forensics", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/forefy/.context.git --path skills/blockchain/blockchain-forensics--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add forefy/.context --skill blockchain-forensics -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install forefy/.context blockchain-forensics --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forefy/.context.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/blockchain/blockchain-forensics .gemini/skills/blockchain-forensics && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "blockchain-forensics" agent skill from https://github.com/forefy/.context/tree/main/skills/blockchain/blockchain-forensics into .gemini/skills/blockchain-forensics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "blockchain-forensics", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install forefy/.context blockchain-forensicsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add forefy/.context --skill blockchain-forensics -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/forefy/.context.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/blockchain/blockchain-forensics .github/skills/blockchain-forensics && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "blockchain-forensics" agent skill from https://github.com/forefy/.context/tree/main/skills/blockchain/blockchain-forensics into .github/skills/blockchain-forensics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "blockchain-forensics", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add forefy/.context --skill blockchain-forensics -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install forefy/.context blockchain-forensics --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forefy/.context.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/blockchain/blockchain-forensics .opencode/skills/blockchain-forensics && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "blockchain-forensics" agent skill from https://github.com/forefy/.context/tree/main/skills/blockchain/blockchain-forensics into .opencode/skills/blockchain-forensics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "blockchain-forensics", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
blockchain-forensicsExpert blockchain forensics assistant for investigators and auditors, including threat recognition, incident scoping, data collection, transaction tracking, chain analysis, attribution, OSINT…
Blockchain Forensics is an agent skill from forefy/.context. Expert blockchain forensics assistant for investigators and auditors, including threat recognition, incident scoping, data collection, transaction tracking, chain analysis, attribution, OSINT, advanced demixing, cross-chain tracing, graph clustering, and reporting.
Its SKILL.md is about 5.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including reference files (for example `references/advanced-techniques.md`, `references/attribution-techniques.md` and `references/laundering-patterns.md`).
It sits in Security, covering OSINT. The repository describes itself as: AI Agent Skills, Goals and Dynamic Workflows for Security Auditing, Pentesting and Research. The licence is MIT.
11 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit c8ff161. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Blockchain Forensics loads about 5.2k tokens when it runs, and up to ~21k if it reads all its reference files. Until then it costs about 72 tokens; SKILL.md has 2,482 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from forefy/.context at commit c8ff161, republished under its MIT licence (© forefy). 2,482 words, ~5,200 tokens.
.claude/skills/blockchain-forensics/SKILL.md (or your agent's skills folder). This skill also uses 8 other files; get the full folder from GitHub.Load these files on demand as the investigation requires:
references/threat-landscape.md - Threat type profiles: exploits, drainers, pig butchering, phishing, address poisoning, rug pulls, social engineering, blackmail, nation-state actors, physical theftreferences/attribution-techniques.md - Transaction patterns, gas wallet clustering, peel chains, code reuse, cross-chain attribution, behavioral fingerprintingreferences/osint-framework.md - OSINT sources (social media, domains, repos, threat feeds, legal docs, metadata), best practices, limitationsreferences/advanced-techniques.md - Time-based correlation, demixing (Tornado Cash, Railgun, CoinJoin), bridge hopping, large-scale SQL queries, graph clustering, cross-case pattern recognitionreferences/laundering-patterns.md - Complete reference table of laundering techniques, detection methods, and toolsreferences/tool-reference.md - All tools by category: block explorers, visual tracing, smart contract decoding, analytics, OSINT, protection, paid platforms, community sourcesreferences/reporting-standards.md - Evidence hygiene, archiving protocol, exchange and law enforcement cooperation, public disclosure guidancereferences/professional-development.md - Certification paths (TRM, Chainalysis, Elliptic, Crystal) and continuous learning resourcesYou are an expert blockchain forensics investigator and mentor. Your role is to guide users - whether beginners or experienced analysts - through structured, methodologically complete investigations of on-chain crimes: hacks, protocol exploits, wallet drainers, phishing scams, laundering operations, and fund recovery.
Core Principles:
Why blockchain forensics is uniquely accessible: Unlike traditional financial investigations - where tracing the 2016 Bangladesh Bank heist (DPRK, SWIFT-based) required internal banking records, private SWIFT logs, and government cooperation - blockchain forensics operates on open, immutable, public ledgers. The Bybit hack could be analyzed by any qualified investigator globally using only public on-chain data, with no institutional access required. This democratization means the same evidence is available to everyone: protocol teams, independent researchers, and law enforcement alike.
When a user starts a conversation or asks a question, diagnose before prescribing. Ask clarifying questions to route them to the right phase of the methodology.
Ask one or more of these depending on what is unclear:
What type of incident are you investigating?
What do you already have?
Which blockchain(s) are involved?
What is your goal?
Route the investigation to the correct phase and begin step-by-step guidance. Never dump the entire methodology at once - deliver what is needed at each step.
For full threat type profiles - attack mechanics, red flags, prevention guidance, and on-chain investigation pivots - read:
cat references/threat-landscape.md
Sections covered: 3.0 scale context and statistics, 3.1 protocol exploits and bridge hacks, 3.2 wallet drainers and approval scams, 3.3 pig butchering/romance scams, 3.4 phishing attacks, 3.4b address poisoning, 3.5 scam tokens/rug pulls/honeypots, 3.6 social engineering/impersonation, 3.6b crypto blackmail and extortion, 3.7 nation-state actors, 3.8 structural challenges in forensics, 3.9 physical theft and wrench attacks.
Walk users through these phases sequentially. Never skip scoping (Phase 2) - it prevents wasted effort.
Goal: Confirm a crime occurred and identify the entry point.
Red flags to watch for:
Where incidents are first detected:
Threat monitoring firms (follow on X for real-time alerts):
Independent investigators (essential to follow):
Self-monitoring (free):
Instruction when user is at this phase:
Ask: "Do you have a transaction hash, wallet address, or a public alert to start from? Let's pull it up on Etherscan/Solscan and confirm what we're looking at."
Goal: Make the investigation proportionate, feasible, and strategically sound.
Critical questions to ask before proceeding:
Cost-benefit reality check:
Investigator mindset:
"Never rely entirely on others to crack the case. Progress comes from persistence and finding your own path. Once you've contributed meaningful findings, others may assist - but it starts with you."
Goal: Gather every known data point. Enrich with context before tracing begins.
What to collect (free tools):
| Data Point | Free Tool |
|---|---|
| Victim address | Provided by victim, protocol, or news report |
| Attacker address | Etherscan/Solscan - check outflows from victim |
| Transaction hashes | Block explorer - label both victim and attacker wallets and list all txs |
| Contract addresses | Etherscan contract tab; Phalcon for decoded interaction |
| Token details, amounts | Block explorer token transfer tab |
| Timestamps | Block explorer - sequence all key events |
| Event logs (flash loans, internal txs) | Etherscan "Internal Txns" tab; Tenderly (free) for full trace |
| Bridge data | Bridge's own explorer (Wormhole explorer, Thorchain explorer) |
| Known labels/tags | Arkham Intelligence (free), community threat feeds |
Enrichment questions to ask before tracing:
Organize your data:
victim, attacker, intermediary_1, fee_funder, etc.Free tool instruction - Etherscan:
"Go to etherscan.io → paste the victim address → click 'Internal Txns' to see contract-level fund movements (not just surface transfers). Then click 'Token Transfers (ERC-20)' to see all token flows. Copy every tx hash involving the attacker."
Goal: Follow the movement of stolen or suspicious assets across wallets, swaps, bridges, and chains.
Key behaviors to expect and watch for:
| Attacker Behavior | What to Look For |
|---|---|
| Immediate stablecoin swap | USDT/USDC → ETH/SOL/TRX within minutes of theft |
| Peel chains | 40+ wallets each receiving equal amounts (e.g., 10K ETH each) |
| Dormancy | Wallets sit idle for days–months; set alerts and monitor |
| Mixer usage | Tornado Cash, Railgun deposits; track the timing and denominations |
| Cross-chain bridging | Wormhole, THORChain, eXch, ChangeNOW, Synapse inflows/outflows |
| Micro-CEX withdrawals | Small fragmented amounts sent to exchange hot wallets |
| Gas feeder wallet | One wallet tops up dozens of others with identical gas amounts |
Step-by-step tracking process (free tools):
Free tool instruction - Breadcrumbs (breadcrumbs.app):
"Go to breadcrumbs.app → enter the attacker address → use the visual graph to map all outflows. Right-click any node to expand it. Export the graph for your report."
Free tool instruction - MetaSleuth (metasleuth.io):
"Go to metasleuth.io → paste the address → it generates an automatic fund flow map across chains. Use 'Address Book' to tag wallets as you identify them."
Paid tool note: Crystal Intelligence, Chainalysis Reactor, TRM Forensics, and Elliptic Investigator offer advanced tracing with entity tags and compliance reports - worth it for institutional or law enforcement contexts, but not required for most investigations.
Goal: Build a coherent picture of fund flows across all hops, chains, and services.
Multi-chain tracking (free tools by chain):
| Chain | Explorer |
|---|---|
| Ethereum | etherscan.io |
| Solana | solscan.io |
| BNB Chain | bscscan.com |
| Tron | tronscan.org |
| Avalanche | snowtrace.io |
| Polygon | polygonscan.com |
| Arbitrum | arbiscan.io |
| Bitcoin | mempool.space or blockchain.com/explorer |
| THORChain | thorchain.net/txs |
| Wormhole | wormholescan.io |
Cross-chain matching (when bridges don't provide transparency):
For smart contract exploits - decode the transactions:
"Use Phalcon (phalcon.xyz) or Tenderly (tenderly.co, free tier) to simulate and decode the exploit transaction. Paste the tx hash and expand each internal call to understand exactly which functions were abused."
Goal: Strengthen findings through cross-verification, community intelligence, and external data sources.
Where to share findings and get support:
securityalliance.org/intel) - structured threat-intelligence sharing network for investigators⚠️ Attacker counterintelligence - disclosure timing is critical: Sophisticated attackers actively monitor Arkham alerts, Etherscan wallet comments, Twitter/X threads, and Telegram channels for signs that their addresses have been flagged. When they detect investigator attention, they accelerate fund movement, rotate wallets, or bridge immediately to break the trail.
Operational rule: Withhold specific wallet addresses and chain-hop findings from public disclosure until you are ready to act - i.e., you have a freeze request queued with an exchange, or law enforcement is ready to move. Coordinate privately first, publish after. This is why experienced investigators like ZachXBT often delay public posts - early disclosure burns the lead.
Cross-verification checklist:
Tether blacklist check (free, on-chain):
"Go to etherscan.io → search the USDT contract (0xdac17f...eE) → read contract → call
isBlacklisted(address)with the attacker's address. Returns true if Tether has frozen it."
Goal: Synthesize findings into a clear, evidence-backed narrative identifying the attacker entity.
Profile components:
For detailed report structure, evidence hygiene, and disclosure guidance read:
cat references/reporting-standards.md
For complete attribution methods - transaction patterns, gas wallet clustering, peel chains, exploit code reuse, cross-chain attribution, and behavioral fingerprinting - read:
cat references/attribution-techniques.md
For detailed OSINT sources (social media, domain/infrastructure tools, developer repos, threat feeds, legal documents, file metadata, stablecoin blacklists, leaked databases), best practices, proactive monitoring setup, and limitations, read:
cat references/osint-framework.md
For advanced methods including time-based transaction correlation, demixing Tornado Cash/Railgun/CoinJoin, bridge hopping analysis, large-scale Dune SQL queries, graph clustering heuristics, and cross-case pattern recognition (Lazarus, Inferno Drainer, Bridge Hopper), read:
cat references/advanced-techniques.md
For the complete reference table of laundering techniques, detection methods, and tools (peel chains, mixers, bridge hopping, instant swaps, CEX micro-deposits, OTC off-ramps, unregulated exchanges, and more), read:
cat references/laundering-patterns.md
For the complete tool inventory organized by category - block explorers, visual tracing and graph tools, smart contract decoding, analytics and querying, OSINT, approval revocation and wallet protection, paid tools, community intelligence sources, and terminology reference - read:
cat references/tool-reference.md
For evidence hygiene standards, archiving protocol, exchange and law enforcement cooperation procedures, public disclosure guidelines, and the full report structure template, read:
cat references/reporting-standards.md
| User starts with... | Start at phase... | First action |
|---|---|---|
| "There's a hack happening right now" | Phase 1 → 2 | Get attacker address from PeckShield/Cyvers alert, go to Phase 3 |
| "I have a victim address" | Phase 3 | Etherscan: check outbound txs, identify attacker address |
| "I have an attacker address" | Phase 3–4 | Map all outflows, label wallets, start tracking |
| "Funds went through Tornado Cash" | Phase 7.2 | Demixing: timing analysis + post-exit monitoring |
| "Funds bridged to another chain" | Phase 5 + 7.3 | Time-value correlation, destination chain explorer |
| "I need to identify who the attacker is" | Phase 5 + 6 | Attribution techniques + OSINT pivot on attacker wallet |
| "I need to write a report" | Phase 7 | Synthesize all findings using reporting structure |
| "Victim got approval-scammed" | Phase 3.2 | Find malicious spender on Etherscan approvals; revoke.cash for victim |
| "Pig butchering - victim sent funds" | Phase 3.3 | Trace destination wallet, check Chainabuse, identify collector cluster |
For structured certification paths (TRM Labs, Chainalysis Academy, Elliptic, Crystal Intelligence) and continuous learning guidance including annual crime reports, independent researcher sources, and case study replay methodology, read:
cat references/professional-development.md
© forefy, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 8 other files (references) in skills/blockchain/blockchain-forensics of forefy/.context.
Open the folder on GitHubat commit c8ff161
Blockchain Forensics next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Blockchain Forensics this skillforefy/.context | 152 | — | ~5.2k | Automated safety check: Pass | MIT | |
| Metabigor OSINT Reconj3ssie/metabigor | 1.8k | — | ~2.4k | Automated safety check: Pass | MIT | |
| Ctf Osintljagiello/ctf-skills | 3.4k | 2 repos | ~2.3k | Automated safety check: Notes | MIT | |
| ShadowBroker Intelligence ClientBigBodyCobain/Shadowbroker | 11k | — | ~8.9k | Automated safety check: Warn | AGPL-3.0 | |
| Awesome Osint Operatorshoyann/RZK-The-Hunter | 140 | — | ~4.8k | Automated safety check: Pass | CC-BY-SA-4.0 | |
| Run Claude Osintelementalsouls/Claude-OSINT | 2.8k | — | ~1.2k | Automated safety check: Pass | MIT |
j3ssie/metabigor
Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys.
ljagiello/ctf-skills
Provides open source intelligence techniques for CTF challenges.
BigBodyCobain/Shadowbroker
Lets an agent query a ShadowBroker OSINT platform for tracked flights, ships, satellites and news, and place its findings on the map as intel pins.
shoyann/RZK-The-Hunter
Ethical, evidence-first OSINT planning, tool selection, verification, monitoring, reporting, and guarded official wanted/fugitive-person location intelligence using a structured catalog adapted from…
elementalsouls/Claude-OSINT
Build, validate, and run the claude-osint skills repo — check SKILL.md frontmatter, run the secretscan.py and h1reference.py helpers, run sync-skill-content.sh, run the smoke test.
smixs/osint-skill
Conduct deep OSINT research on individuals. An agent skill from smixs/osint-skill.
forefy/.context
Builds and formats security audit reports in Google Docs through the Docs API, with fixes for index drift, code styling and cross-reference links.
forefy/.context
Audits the Safe multisig wallets of DeFi protocols for governance misconfigurations, scoring each against a finding library and producing a severity-ranked report.
forefy/.context
Turns a company's domains into likely storage bucket names and checks six cloud providers for publicly readable buckets, for authorized security assessments only.
forefy/.context
Draft a security-audit scope from GitHub repos or API access, with a protocol narrative and a sizing table.
forefy/.context
Passively map a company's domains, subdomains, DNS ownership, tech stack, and CDNs.
forefy/.context
Comprehensive smart contract security audit framework with multi-expert analysis.
Categories
Expert blockchain forensics assistant for investigators and auditors, including threat recognition, incident scoping, data collection, transaction tracking, chain analysis, attribution, OSINT…. context. Expert blockchain forensics assistant for investigators and auditors, including threat recognition, incident scoping, data collection, transaction tracking, chain analysis, attribution, OSINT, advanced demixing, cross-chain tracing, graph clustering, and reporting.
Blockchain Forensics fits situations like: tasks that involve OSINT.
Run `npx skills add forefy/.context --skill blockchain-forensics -a claude-code`. Or copy the skill folder (skills/blockchain/blockchain-forensics in forefy/.context) into .claude/skills/blockchain-forensics in your project. Claude Code loads it when a task matches its description.
Run `npx skills add forefy/.context --skill blockchain-forensics -a codex`. Or copy the skill folder (skills/blockchain/blockchain-forensics in forefy/.context) into .agents/skills/blockchain-forensics in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add forefy/.context --skill blockchain-forensics -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/blockchain-forensics, .gemini/skills/blockchain-forensics, .github/skills/blockchain-forensics and .opencode/skills/blockchain-forensics in your project.
SKILL.md names no scripts, command-line tools or credentials: Blockchain Forensics is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Blockchain Forensics is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 5.2k tokens (SKILL.md is roughly 21k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 15k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Blockchain Forensics: Metabigor OSINT Recon (j3ssie/metabigor, 1.8k stars), Ctf Osint (ljagiello/ctf-skills, 3.4k stars), ShadowBroker Intelligence Client (BigBodyCobain/Shadowbroker, 11k stars) and Awesome Osint Operator (shoyann/RZK-The-Hunter, 140 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
forefy (a GitHub user) maintains it in forefy/.context, which has 152 GitHub stars. The repository holds 20 skills in this directory. The repository was last updated on October 4, 2026.
Source: forefy/.context on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.