Agent skill

Metabigor OSINT Recon

by j3ssie in j3ssie/metabigor

Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys.

MITAuto-check passedSecurity

Install Metabigor OSINT Recon

skills CLI
$ npx skills add j3ssie/metabigor --skill metabigor -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install j3ssie/metabigor metabigor --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/j3ssie/metabigor.git skills-src && mkdir -p .claude/skills && cp -r skills-src/public/skills/metabigor .claude/skills/metabigor && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
metabigor
GitHub stars
1.8k
Token cost
~2.4k tokens
SKILL.md length
789 words
Files
3 (incl. references)
Skills in repo
1
Repo updated
First seen
Licence
MIT

At a glance

Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys.

  • Mapping the network ranges behind an ASN, organization or domain
  • SKILL.md covers TL;DR, Mental model, The four ways to pass targets and Command router, plus 6 more sections
  • Calls jq; needs VT_API_KEY and VIRUSTOTAL_API_KEY
  • Enumerating subdomains of a domain from certificate logs

What it does

Metabigor is a command-line OSINT tool, part of the Osmedeus Engine, that maps infrastructure from free sources. The skill covers each subcommand: net for network ranges from an ASN, organization, domain or IP; cert for subdomains from certificate logs; ip for ports and CVEs through Shodan InternetDB; github for secrets and subdomains in public code; cluster for grouping IPs by ASN; related for pivoting through crt.sh, WHOIS and analytics; cdn for spotting CDN and WAF vendors and candidate origins; url for archived URLs and WARC-mined endpoints; and update for the offline databases.

Every command accepts targets in the same four ways, and the merged list is deduplicated. Results go to stdout and logs to stderr, one -f flag picks text, flat, json or csv, the flat format emits the bare primary value so one command feeds the next, and failures exit non-zero so it fits scripts and CI. The net and cluster commands work offline from a bundled database, and the url command optionally reads keys from environment variables only. Reference files hold recipes and details of the url command.

When your agent uses it

  • Mapping the network ranges behind an ASN, organization or domain
  • Enumerating subdomains of a domain from certificate logs
  • Finding likely origin servers behind a CDN or WAF
  • Chaining several recon commands into one pipeline

Example prompts

  • “List the CIDR ranges behind AS13335 with metabigor.”
  • “Enumerate subdomains of example.com from certificate logs and strip the wildcard entries.”
  • “Build a recon pipeline that chains net, cluster and ip for a company name.”

Requirements

  • The metabigor CLI

What it can do on your machine

Read from SKILL.md and the folder at commit 5785d65. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • twitter.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • VT_API_KEY
    • VIRUSTOTAL_API_KEY
    • INTELX_API_KEY
    • URLSCAN_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Metabigor OSINT Recon loads about 2.4k tokens when it runs, and up to ~3.8k if it reads all its reference files. Until then it costs about 167 tokens; SKILL.md has 789 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~167
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from j3ssie/metabigor at commit 5785d65, republished under its MIT licence (© j3ssie). 789 words, ~2,388 tokens.

Download SKILL.mdSave it as .claude/skills/metabigor/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
metabigor
description
Use when operating the metabigor CLI for OSINT recon and infrastructure mapping without API keys. Covers finding network ranges from an ASN, org, domain, or IP (net); enumerating subdomains from certificate logs (cert); enriching IPs with ports/CVEs via Shodan InternetDB (ip); searching public GitHub code for secrets and subdomains (github); clustering IPs by ASN (cluster); pivoting to related domains via crt.sh/WHOIS/analytics (related); detecting CDN/WAF vendors and isolating candidate origins (cdn); collecting archived URLs and WARC-mined endpoints (url); refreshing the offline databases (update); and chaining these commands into a recon pipeline.
license
MIT
tags
osint, recon, subdomain-enumeration, asn, network-discovery

Metabigor

CLI-first OSINT tool that maps a target's infrastructure from free sources, no API keys. Part of the Osmedeus Engine. Every command takes targets the same four ways and renders through one -f/--format flag, so any command pipes cleanly into the next.

TL;DR

bash
metabigor net AS13335                  # network ranges (CIDRs) behind an ASN
metabigor cert hackerone.com           # subdomains from certificate logs
metabigor ip 1.1.1.1                   # open ports + CVEs for an IP (free, no key)
metabigor related tesla.com            # other domains the target owns
metabigor cdn --exclude -I ips.txt     # drop CDN/WAF IPs, keep candidate origins
metabigor url hackerone.com -f flat    # every archived URL, ready to pipe

metabigor <command> -h is authoritative for the version you have installed.

Mental model

  • Zero configuration, no API keys. net/cluster work fully offline from a bundled database. The url command optionally reads keys from the environment only (VT_API_KEY/VIRUSTOTAL_API_KEY, INTELX_API_KEY, URLSCAN_API_KEY) — never from a flag or config file.
  • Results to stdout, logs to stderr. Pipes stay clean at any log level, so metabigor cert x.com | other-tool always works. Progress is quiet by default; add -v for step-by-step lines.
  • One output flag. -f/--format text|flat|json|csv covers every command. There are no per-command format flags.
  • Everything composes. The flat format emits the bare primary value so one command's output is the next command's input.
  • Non-zero exit on failure, so metabigor drops into &&, set -e, and CI.

The four ways to pass targets

Identical on every command; the merged list is deduplicated.

bash
metabigor cert example.com                 # as an argument
metabigor cert example.com tesla.com       # several arguments
metabigor cert -i example.com              # with -i (use when a target looks like a flag)
metabigor cert -I domains.txt              # from a file, one per line (# comments ignored)
cat domains.txt | metabigor cert           # on stdin

Stdin is read only when no target was given another way, so metabigor net AS13335 never blocks inside a script or CI job.

Command router

I need to…Use
Find CIDRs announced by an ASNmetabigor net AS13335
Find which ASN owns an IPmetabigor net 1.1.1.1 --detail
Find ranges by company namemetabigor net --org Cloudflare
Query live BGP sources, not the local DBmetabigor net --live tesla.com
Enumerate subdomains from cert logsmetabigor cert hackerone.com
Cert search by organizationmetabigor cert "HackerOne Inc"
Strip *. from wildcard cert entriesmetabigor cert example.com --clean
Cert IDs, issuers, validity datesmetabigor cert example.com --detail
Ports / hostnames / CVEs for an IPmetabigor ip 1.1.1.1
Enrich a whole CIDRmetabigor ip 1.1.1.0/28
Search public GitHub code (grep.app)metabigor github hackerone.com
Pull only subdomains out of code matchesmetabigor github tesla.com --subs
Show the matching code linesmetabigor github "api_key=" --detail
Group IPs by owning ASNmetabigor cluster -I ips.txt
Pivot to related domains (all sources)metabigor related hackerone.com
Pivot via specific sourcesmetabigor related tesla.com --sources crt,whois
Collect archived URLs (keyless sources)metabigor url hackerone.com
Scope URL collection to one hostmetabigor url blog.hackerone.com --no-subs
Detect CDN/WAF vendor for an IPmetabigor cdn 1.1.1.1
Drop CDN/WAF IPs, keep originsmetabigor cdn --exclude -I ips.txt
Keep only CDN/WAF-protected IPsmetabigor cdn --only -I ips.txt
Refresh the offline ASN/country DBsmetabigor update
Print / install these agent skillsmetabigor skills get --full

Output formats

-f/--format on every command. Default is text.

FormatFlagWhat you getUse it for
Text (default)-f textReadable `ab
Flat-f flatThe bare primary value, one per linePiping into other tools
JSON-f jsonOne JSON object per linejq, automation
CSV-f csvRows behind one headerSpreadsheets, reports
bash
metabigor ip 1.1.1.0/28                 # 1.1.1.1 | 80,443 | one.one.one.one
metabigor ip 1.1.1.0/28 -f flat         # 1.1.1.1:80
metabigor ip 1.1.1.0/28 -f json | jq .  # {"ip":"1.1.1.1","ports":[80,443],...}
metabigor ip 1.1.1.0/28 -f csv -o ports.csv

-o <file> also writes results to a file (overwrite; --append to add).

Show full SKILL.md (299 more words)Show less

Per-command notes

Things -h alone won't make obvious.

  • net auto-detects the target type; override with --asn, --ip, --domain, or --org (mutually exclusive). --detail adds ASN / org / country columns. --live swaps the offline DB for live BGP sources (bgp.he.net) — slower, but current.
  • cert prints a plain domain list by default. --detail gives the grouped certificate view (IDs, issuers, dates); --clean strips *.; --wildcard keeps only wildcard entries. Feed it into a resolver: metabigor cert t.com | dnsx -silent.
  • ip uses Shodan InternetDB (free, no key). IPs it knows nothing about are skipped; pass --all to keep them. CIDRs expand to hosts.
  • github needs Chrome/Chromium (grep.app blocks plain HTTP clients). Searches run one at a time regardless of -c to respect grep.app's rate limit. --subs returns subdomains only; --detail shows code; --pages N goes deeper.
  • cluster groups IPs/CIDRs by owning ASN, largest cluster first. Fully offline.
  • related sources: crt (crt.sh), whois (viewdns.info reverse WHOIS), analytics (shared Google Analytics / Tag Manager IDs), or all (default). Results are deduped across sources and tagged with the first source that found each.
  • cdn classifies IPs by CDN/WAF vendor. --exclude drops protected IPs (leaving candidate origins); --only keeps just the protected ones. The two are mutually exclusive.
  • url includes subdomains by default (queries *.target) — the single biggest lever on volume; --no-subs narrows it. GhostArchive is mined: its WARCs expose sub-request URLs (XHR/JSON endpoints) that no CDX index lists. Filters are off by default. See references/url-command.md.
  • update refreshes both the IP-to-ASN and IP-to-country databases in ~/.metabigor. A copy ships with the binary and unpacks on first use, so this is only needed to pick up newer routing data.

Global flags

  -i, --input string        Target to look up (also accepts arguments or stdin)
  -I, --input-file string   File of targets, one per line (use - for stdin)
  -o, --output string       Also write results to this file
  -f, --format string       Output format: text, json, csv, flat (default "text")
      --append              Append to the output file instead of overwriting it
  -c, --concurrency int     Number of parallel workers (default 10)
  -t, --timeout int         Request timeout in seconds (default 40)
      --retry int           Retries per failed request (default 3)
      --proxy string        Upstream proxy, e.g. http://127.0.0.1:8080
  -v, --verbose             Show step-by-step progress
  -q, --quiet               Show results and errors only
      --debug               Show HTTP traffic and internal traces (implies --verbose)
      --no-color            Disable colored log output

Recon pipeline

The point of the flat format: chain commands into a workflow.

bash
# ASN -> ranges -> live hosts with ports
metabigor net AS13335 -f flat | metabigor ip -f flat

# domain -> related domains -> their subdomains
metabigor related tesla.com -f flat | metabigor cert

# resolve subdomains, then split CDN from candidate origins
metabigor cert tesla.com | dnsx -silent -resp-only | metabigor cdn --exclude

# collect archived URLs and probe them
metabigor url tesla.com -f flat | httpx -silent

More multi-step workflows: references/recipes.md.

Escape hatches

bash
metabigor <command> -h     # authoritative flags for your installed version
metabigor version          # version, build date, commit
metabigor skills get --full  # print this skill and every reference

Resources

© j3ssie, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in public/skills/metabigor of j3ssie/metabigor.

  • SKILL.md
  • references/recipes.md
  • references/url-command.md

Open the folder on GitHubat commit 5785d65

Compare with similar skills

Metabigor OSINT Recon next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Metabigor OSINT Recon compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Metabigor OSINT Recon this skillj3ssie/metabigor1.8k—~2.4kAutomated safety check: PassMIT
External Recon PlaybookPentesterFlow/agent1.4k—~1.2kAutomated safety check: PassApache-2.0
Vulnerability Lookupptn1411/skill220—~1.1kAutomated safety check: PassNone
Wooyun Legacytanweai/wooyun-legacy1.8k—~1.9kAutomated safety check: PassCustom licence
Client Request Signature Reversalawarexone/Agentic-Bug-Hunter5.3k—~4.7kAutomated safety check: PassMIT
Web3 Bug Bounty AI Toolstradecatlabs/vibe-coding-cn17k2 repos~3.9kAutomated safety check: WarnMIT

Similar skills

  • External Recon Playbook

    PentesterFlow/agent

    Maps the attack surface of a web domain you are authorized to test: confirms scope, lists subdomains from public sources, probes live hosts and fingerprints technology.

    1.4k GitHub stars~1.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Multi-source threat intelligence and vulnerability lookup. An agent skill from ptn1411/skill.

    220 GitHub stars~1.1k tokensUpdated 17 days ago
    SecurityAuto-check passed
  • Wooyun Legacy

    tanweai/wooyun-legacy

    WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…

    1.8k GitHub stars~1.9k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Client Request Signature Reversal

    awarexone/Agentic-Bug-Hunter

    Recovers a client-side request signature or anti-bot token just far enough to replay blocked requests in bug bounty testing, starting from a captured packet.

    5.3k GitHub stars~4.7k tokensUpdated yesterday
    SecurityAuto-check passed
  • Web3 Bug Bounty AI Tools

    tradecatlabs/vibe-coding-cn

    A selection guide to AI-driven tools for Web3 bug bounty work, from autonomous web pentesters to smart contract bug finders, with notes on authorization.

    17k GitHub starsUsed in 2 repos~3.9k tokens
    SecurityAuto-check: warnings
  • Add Partial Recon

    samugit83/redamon

    Adding partial-recon support for a tool: running a single pipeline phase on demand from the workflow graph, reading its inputs from the existing Neo4j graph and merging results back.

    3k GitHub stars~1.1k tokensUpdated yesterday
    SecurityAuto-check passed

Works with

Categories

Questions about Metabigor OSINT Recon

What does Metabigor OSINT Recon do?

Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys. Metabigor is a command-line OSINT tool, part of the Osmedeus Engine, that maps infrastructure from free sources.sh, WHOIS and analytics; cdn for spotting CDN and WAF vendors and candidate origins; url for archived URLs and WARC-mined endpoints; and update for the offline databases.

When should I use Metabigor OSINT Recon?

Metabigor OSINT Recon fits situations like: mapping the network ranges behind an ASN, organization or domain; enumerating subdomains of a domain from certificate logs; finding likely origin servers behind a CDN or WAF; chaining several recon commands into one pipeline.

How do I install Metabigor OSINT Recon in Claude Code?

Run `npx skills add j3ssie/metabigor --skill metabigor -a claude-code`. Or copy the skill folder (public/skills/metabigor in j3ssie/metabigor) into .claude/skills/metabigor in your project. Claude Code loads it when a task matches its description.

How do I install Metabigor OSINT Recon in Codex?

Run `npx skills add j3ssie/metabigor --skill metabigor -a codex`. Or copy the skill folder (public/skills/metabigor in j3ssie/metabigor) into .agents/skills/metabigor in your project. Codex loads it when a task matches its description.

Can I use Metabigor OSINT Recon in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add j3ssie/metabigor --skill metabigor -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/metabigor, .gemini/skills/metabigor, .github/skills/metabigor and .opencode/skills/metabigor in your project.

What does Metabigor OSINT Recon need to run?

Going by SKILL.md and its folder, Metabigor OSINT Recon needs the command-line tools its instructions call (jq) and credentials named VT_API_KEY, VIRUSTOTAL_API_KEY, INTELX_API_KEY and URLSCAN_API_KEY. Our summary lists: The metabigor CLI.

Does Metabigor OSINT Recon access the network?

SKILL.md names 1 domain. As links in the text: twitter.com. This is read from the text; nothing was executed.

Is Metabigor OSINT Recon safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Metabigor OSINT Recon use?

Metabigor OSINT Recon is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Metabigor OSINT Recon use?

About 2.4k tokens (SKILL.md is roughly 9.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.4k tokens, read only when the agent opens those files.

What are the alternatives to Metabigor OSINT Recon?

Skills that share tags, products or a category with Metabigor OSINT Recon: External Recon Playbook (PentesterFlow/agent, 1.4k stars), Vulnerability Lookup (ptn1411/skill, 220 stars), Wooyun Legacy (tanweai/wooyun-legacy, 1.8k stars) and Client Request Signature Reversal (awarexone/Agentic-Bug-Hunter, 5.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Metabigor OSINT Recon?

j3ssie (a GitHub user) maintains it in j3ssie/metabigor, which has 1,849 GitHub stars. The repository was last updated on August 8, 2026.

Source: j3ssie/metabigor on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.