Agent skill

Osint Investigation

by johnson7788 in johnson7788/MultiUserClaw

Public-records OSINT investigation framework — SEC EDGAR filings, USAspending contracts, Senate lobbying, OFAC sanctions, ICIJ offshore leaks, NYC property records (ACRIS), OpenCorporates…

MITAuto-check passedSecurity

Install Osint Investigation

skills CLI
$ npx skills add johnson7788/MultiUserClaw --skill osint-investigation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install johnson7788/MultiUserClaw osint-investigation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/johnson7788/MultiUserClaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/hermes-agent/optional-skills/research/osint-investigation .claude/skills/osint-investigation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
osint-investigation
GitHub stars
327
Token cost
~3k tokens
SKILL.md length
931 words
Files
30 (incl. scripts, references)
Skills in repo
9
Repo updated
First seen
Licence
MIT

At a glance

Public-records OSINT investigation framework — SEC EDGAR filings, USAspending contracts, Senate lobbying, OFAC sanctions, ICIJ offshore leaks, NYC property records (ACRIS), OpenCorporates…

  • Works in 5 steps: Identify which sources apply → Acquire data → Resolve entities across sources → …
  • Tasks that involve OSINT
  • SKILL.md covers When to use this skill, Workflow, Confidence and evidence… and Adding a new data source, plus 2 more sections
  • Runs Python scripts from its folder; calls python3; needs OPENCORPORATES_API_TOKEN and SENATE_LDA_TOKEN

What it does

Osint Investigation is an agent skill from johnson7788/MultiUserClaw. Public-records OSINT investigation framework — SEC EDGAR filings, USAspending contracts, Senate lobbying, OFAC sanctions, ICIJ offshore leaks, NYC property records (ACRIS), OpenCorporates registries, CourtListener court records, Wayback Machine archives, Wikipedia + Wikidata, GDELT news monitoring. Entity resolution across sources, cross-link analysis, timing correlation, evidence chains. Python stdlib only.

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 32 other files, including scripts and reference files (for example `references/sources/courtlistener.md`, `references/sources/gdelt.md` and `references/sources/icij-offshore.md`).

It sits in Security, covering OSINT. It works with Python, Wikipedia and SEC EDGAR. The repository describes itself as: 目前OpenClaw和NanoBot都是用于个人的,不太支持多用户,基于多用户重新修改Bot,没有对Openclaw进行任何更改,原生能力封装. The licence is MIT.

When your agent uses it

  • Tasks that involve OSINT

Example prompts

  • “/osint-investigation”

Requirements

  • Python 3
  • A credential in DEMO_KEY
  • A credential in OPENCORPORATES_API_TOKEN

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Identify which sources apply
  2. Acquire data
  3. Resolve entities across sources
  4. Statistical timing correlation (optional)
  5. Build the findings JSON (evidence chain)

What it can do on your machine

Read from SKILL.md and the folder at commit 2f88dfa. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 6 files in scripts/ (Python, from the files we listed), which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • fec.gov

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • OPENCORPORATES_API_TOKEN
    • SENATE_LDA_TOKEN
    • COURTLISTENER_TOKEN
    • DEMO_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Osint Investigation loads about 3k tokens when it runs, and up to ~13k if it reads all its reference files. Until then it costs about 108 tokens; SKILL.md has 931 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~108
When it runs · the whole SKILL.md, loaded when a task matches
~3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~13k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from johnson7788/MultiUserClaw at commit 2f88dfa, republished under its MIT licence (© johnson7788). 931 words, ~2,993 tokens.

Download SKILL.mdSave it as .claude/skills/osint-investigation/SKILL.md (or your agent's skills folder). This skill also uses 29 other files; get the full folder from GitHub.
name
osint-investigation
description
Public-records OSINT investigation framework — SEC EDGAR filings, USAspending contracts, Senate lobbying, OFAC sanctions, ICIJ offshore leaks, NYC property records (ACRIS), OpenCorporates registries, CourtListener court records, Wayback Machine archives, Wikipedia + Wikidata, GDELT news monitoring. Entity resolution across sources, cross-link analysis, timing correlation, evidence chains. Python stdlib only.
version
0.1.0
platforms
linux, macos, windows
author
Hermes Agent (adapted from ShinMegamiBoson/OpenPlanter, MIT)

OSINT Investigation — Public Records Cross-Reference

Investigative framework for public-records OSINT: government contracts, corporate filings, lobbying, sanctions, offshore leaks, property records, court records, web archives, knowledge bases, and global news. Resolve entities across heterogeneous sources, build cross-links with explicit confidence, run statistical timing tests, and produce structured evidence chains.

Python stdlib only. Zero install. Works on Linux, macOS, Windows. Most sources work with no API key (OpenCorporates has an optional free token that raises rate limits).

Adapted from the MIT-licensed ShinMegamiBoson/OpenPlanter project; expanded to cover identity / property / litigation / archives / news sources that the original didn't address.

When to use this skill

Use when the user asks for:

  • "follow the money" — government contracts, lobbying → legislation, sanctions
  • corporate due diligence — who controls company X, where are they incorporated, who serves on their boards, what filings have they made
  • sanctions screening — is entity X on OFAC SDN, ICIJ offshore leaks
  • pay-to-play investigation — contractors with offshore ties, lobbying clients winning awards
  • property ownership — find recorded deeds/mortgages by name or address (NYC; for other counties point users at the relevant recorder)
  • litigation history — find federal + state court opinions and PACER dockets
  • multi-source entity resolution where naming varies (LLC suffixes, abbreviations)
  • evidence-chain construction with explicit confidence levels
  • "what's been said about X" — international news (GDELT) + Wikipedia narrative + Wayback Machine to recover dead URLs

Do NOT use this skill for:

  • general web research → web_search / web_extract
  • domain/infrastructure OSINT → domain-intel skill
  • academic literature → arxiv skill
  • social-media profile discovery → sherlock skill (optional)
  • US federal campaign finance — FEC is intentionally NOT covered here (the API is unreliable for ad-hoc contributor-name queries on the free DEMO_KEY tier). For federal donations, point users at https://www.fec.gov/data/ directly.

Workflow

The agent runs scripts via the terminal tool. SKILL_DIR is the directory holding this SKILL.md.

1. Identify which sources apply

Read the data-source wiki entries to plan the investigation:

ls SKILL_DIR/references/sources/

# Federal financial / regulatory
cat SKILL_DIR/references/sources/sec-edgar.md       # corporate filings
cat SKILL_DIR/references/sources/usaspending.md     # federal contracts
cat SKILL_DIR/references/sources/senate-ld.md       # lobbying
cat SKILL_DIR/references/sources/ofac-sdn.md        # sanctions
cat SKILL_DIR/references/sources/icij-offshore.md   # offshore leaks

# Identity / property / litigation / archives / news
cat SKILL_DIR/references/sources/nyc-acris.md       # NYC property records
cat SKILL_DIR/references/sources/opencorporates.md  # global corporate registry
cat SKILL_DIR/references/sources/courtlistener.md   # court records (federal + state)
cat SKILL_DIR/references/sources/wayback.md         # Wayback Machine archives
cat SKILL_DIR/references/sources/wikipedia.md       # Wikipedia + Wikidata
cat SKILL_DIR/references/sources/gdelt.md           # global news monitoring

Each entry follows a 9-section template: summary, access, schema, coverage, cross-reference keys, data quality, acquisition, legal, references.

The cross-reference potential section maps join keys between sources — read those first to pick the right pair.

2. Acquire data

Each source has a stdlib-only fetch script in SKILL_DIR/scripts/:

Federal financial / regulatory

bash
# SEC EDGAR filings (corporate disclosures)
python3 SKILL_DIR/scripts/fetch_sec_edgar.py --cik 0000320193 \
    --types 10-K,10-Q --out data/edgar_filings.csv

# USAspending federal contracts
python3 SKILL_DIR/scripts/fetch_usaspending.py --recipient "EXAMPLE CORP" \
    --fy 2024 --out data/contracts.csv

# Senate LD-1 / LD-2 lobbying disclosures
python3 SKILL_DIR/scripts/fetch_senate_ld.py --client "EXAMPLE CORP" \
    --year 2024 --out data/lobbying.csv

# OFAC SDN sanctions list (full snapshot)
python3 SKILL_DIR/scripts/fetch_ofac_sdn.py --out data/ofac_sdn.csv

# ICIJ Offshore Leaks — downloads ~70 MB bulk CSV on first use,
# then searches it locally. Cached for 30 days under
# $HERMES_OSINT_CACHE/icij/ (default: ~/.cache/hermes-osint/icij/).
python3 SKILL_DIR/scripts/fetch_icij_offshore.py --entity "EXAMPLE CORP" \
    --out data/icij.csv

Identity / property / litigation / archives / news

bash
# NYC property records (deeds, mortgages, liens) — ACRIS via Socrata
python3 SKILL_DIR/scripts/fetch_nyc_acris.py --name "SMITH, JOHN" \
    --out data/acris.csv
python3 SKILL_DIR/scripts/fetch_nyc_acris.py --address "571 HUDSON" \
    --out data/acris_addr.csv

# OpenCorporates — 130+ jurisdiction corporate registry
# (free token required; set OPENCORPORATES_API_TOKEN or pass --token)
python3 SKILL_DIR/scripts/fetch_opencorporates.py --query "Example Corp" \
    --jurisdiction us_ny --out data/opencorporates.csv

# CourtListener — federal + state court opinions, PACER dockets
python3 SKILL_DIR/scripts/fetch_courtlistener.py --query "Smith v. Example Corp" \
    --type opinions --out data/courts.csv

# Wayback Machine — historical web captures
python3 SKILL_DIR/scripts/fetch_wayback.py --url "example.com" \
    --match host --collapse digest --out data/wayback.csv

# Wikipedia + Wikidata — narrative bio + structured facts
# Set HERMES_OSINT_UA=your-app/1.0 (your@email) to identify yourself
python3 SKILL_DIR/scripts/fetch_wikipedia.py --query "Bill Gates" \
    --out data/wp.csv

# GDELT — global news in 100+ languages, ~2015→present
python3 SKILL_DIR/scripts/fetch_gdelt.py --query '"Example Corp"' \
    --timespan 1y --out data/gdelt.csv

All outputs are normalized CSV with a header row. Re-run scripts idempotently.

When a private individual won't be in a source (e.g. SEC EDGAR for a non-public- company person, USAspending for someone who isn't a federal contractor, Senate LDA for someone who isn't a lobbying client), the script returns 0 rows with a clear warning rather than silently writing an empty CSV. EDGAR specifically flags when the company-name resolver matched an individual Form 3/4/5 filer rather than a corporate registrant.

Rate-limit notes are in each source's wiki entry. Default fetchers sleep politely between paginated requests. API keys raise rate limits for sources that support them (SEC_USER_AGENT, SENATE_LDA_TOKEN, OPENCORPORATES_API_TOKEN, COURTLISTENER_TOKEN). All scripts surface 429 responses immediately with the upstream's quota message so the user knows to slow down or supply a key.

3. Resolve entities across sources

Normalize names and find matches between two CSV files:

bash
# Match lobbying clients (Senate LDA) against contract recipients (USAspending)
python3 SKILL_DIR/scripts/entity_resolution.py \
    --left  data/lobbying.csv   --left-name-col  client_name \
    --right data/contracts.csv  --right-name-col recipient_name \
    --out data/cross_links.csv

Three matching tiers with explicit confidence:

TierMethodConfidence
exactNormalized strings equal after suffix/punctuation striphigh
fuzzySorted-token equality (word-bag match)medium
token_overlap≥60% token overlap, ≥2 shared tokens, tokens ≥4 charslow

Output cross_links.csv columns: match_type, confidence, left_name, right_name, left_normalized, right_normalized, left_row, right_row.

Show full SKILL.md (385 more words)Show less
4. Statistical timing correlation (optional)

Test whether two time series cluster suspiciously close together — e.g. lobbying filings near contract awards — using a permutation test:

bash
python3 SKILL_DIR/scripts/timing_analysis.py \
    --donations data/lobbying.csv --donation-date-col filing_date \
        --donation-amount-col income --donation-donor-col client_name \
        --donation-recipient-col registrant_name \
    --contracts data/contracts.csv --contract-date-col award_date \
        --contract-vendor-col recipient_name \
    --cross-links data/cross_links.csv \
    --permutations 1000 \
    --out data/timing.json

The script's column flags are intentionally generic — the original tool was written for donations vs awards, but it works for any (event, payee) time series joined through cross-links. Null hypothesis: event timing is independent of award dates. One-tailed p-value = fraction of permutations with mean nearest-award distance ≤ observed. Minimum 3 events per (payer, vendor) pair to run the test.

5. Build the findings JSON (evidence chain)
bash
python3 SKILL_DIR/scripts/build_findings.py \
    --cross-links data/cross_links.csv \
    --timing data/timing.json \
    --out data/findings.json

Every finding has id, title, severity, confidence, summary, evidence[], sources[]. Each evidence item points back to a specific row in a source CSV. The user (or a follow-up agent) can verify every claim against its source.

Confidence and evidence discipline

This is the load-bearing rule of the skill. Tell the user:

  • Every claim must trace to a record. No naked assertions.
  • Confidence tier travels with the claim. match_type=fuzzy is "probable", not "confirmed."
  • Entity resolution produces candidates, NOT conclusions. A fuzzy match between "ACME LLC" and "Acme Holdings Group" is a lead, not a fact.
  • Statistical significance ≠ wrongdoing. p < 0.05 means the timing pattern is unlikely under the null. It does not establish corruption.
  • All data sources here are public records. They may still contain inaccuracies, stale info, or redactions (GDPR, sealed records).

Adding a new data source

Use the template:

bash
cp SKILL_DIR/templates/source-template.md \
    SKILL_DIR/references/sources/<your-source>.md

Fill in all 9 sections. Write a fetch_<source>.py script in scripts/ that uses stdlib only and writes a normalized CSV. Update the source list in the "When to use" section above.

Tools and their limits

  • entity_resolution.py does NOT use external fuzzy libraries (no rapidfuzz, no jellyfish). Token-bag matching is the upper bound here. If you need Levenshtein, transliteration, or phonetic matching, pip-install separately.
  • timing_analysis.py uses Python's random for permutations. For reproducibility, pass --seed N.
  • fetch_*.py scripts use urllib.request and respect Retry-After. Heavy bulk usage may still violate ToS — read each source's legal section first.

All Phase-1 sources are public records. Bulk acquisition is permitted under their respective access terms (FOIA, public records law, ICIJ explicit publication, OFAC public data). However:

  • Some sources rate-limit aggressively. Respect their headers.
  • Some redact registrant info (GDPR on WHOIS, sealed filings).
  • Cross-referencing public records to identify private individuals can have ethical implications. The skill produces evidence chains, not accusations.

© johnson7788, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 29 other files (scripts, references) in hermes-agent/optional-skills/research/osint-investigation of johnson7788/MultiUserClaw.

  • SKILL.md
  • references/sources/courtlistener.md
  • references/sources/gdelt.md
  • references/sources/icij-offshore.md
  • references/sources/nyc-acris.md
  • references/sources/ofac-sdn.md
  • references/sources/opencorporates.md
  • references/sources/sec-edgar.md
  • references/sources/senate-ld.md
  • references/sources/usaspending.md
  • references/sources/wayback.md
  • references/sources/wikipedia.md
  • scripts/_http.py
  • scripts/_normalize.py
  • scripts/build_findings.py
  • scripts/entity_resolution.py
  • scripts/fetch_courtlistener.py
  • scripts/fetch_gdelt.py
  • … and 12 more

Open the folder on GitHubat commit 2f88dfa

Compare with similar skills

Osint Investigation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Osint Investigation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Osint Investigation this skilljohnson7788/MultiUserClaw327—~3kAutomated safety check: PassMIT
Domain IntelTommy-yw/RunbookHermes5461 repos~1.1kAutomated safety check: PassMIT
Implementing Stix Taxii Feed Integrationmukul975/Anthropic-Cybersecurity-Skills34k—~2.7kAutomated safety check: PassApache-2.0
Automating Ioc Enrichmentmukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: PassApache-2.0
Building Adversary Infrastructure Tracking Systemmukul975/Anthropic-Cybersecurity-Skills34k—~3.7kAutomated safety check: PassApache-2.0
Building Attack Pattern Library From Cti Reportsmukul975/Anthropic-Cybersecurity-Skills34k—~3.4kAutomated safety check: PassApache-2.0

Similar skills

  • Domain Intel

    Tommy-yw/RunbookHermes

    Passive domain reconnaissance using Python stdlib. An agent skill from Tommy-yw/RunbookHermes.

    546 GitHub starsUsed in 1 repo~1.1k tokens
    SecurityAuto-check passed
  • Implementing Stix Taxii Feed Integration

    mukul975/Anthropic-Cybersecurity-Skills

    Implements a STIX 2.1/TAXII 2.1 threat-intelligence feed consumer and producer in Python, covering TAXII server discovery, collection polling, parsing STIX bundles with the stix2 library, and…

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Automating Ioc Enrichment

    mukul975/Anthropic-Cybersecurity-Skills

    Automates the enrichment of raw indicators of compromise with multi-source threat intelligence context using SOAR platforms, Python pipelines, or TIP playbooks to reduce analyst triage time and…

    34k GitHub stars~2.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Building Adversary Infrastructure Tracking System

    mukul975/Anthropic-Cybersecurity-Skills

    Build an automated adversary infrastructure tracking system in Python (dnspython, python-whois, shodan, networkx) that pivots across passive DNS, certificate transparency logs, WHOIS records, and IP…

    34k GitHub stars~3.7k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Building Attack Pattern Library From Cti Reports

    mukul975/Anthropic-Cybersecurity-Skills

    Parse cyber threat intelligence reports (Mandiant, CrowdStrike, Talos, Microsoft) with stix2, mitreattack-python, and spaCy to extract adversary behaviors, map them to MITRE ATT&CK technique IDs…

    34k GitHub stars~3.4k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Implementing Security Information Sharing With Stix2

    mukul975/Anthropic-Cybersecurity-Skills

    Create, validate, and share STIX 2.1 threat intelligence objects (indicators, malware, campaigns, relationships, bundles) using the stix2 Python library, and publish them over TAXII 2.1.

    34k GitHub stars~3.3k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from johnson7788/MultiUserClaw

All 9 skills in this repo
  • Hyperframes

    johnson7788/MultiUserClaw

    Create HTML-based video compositions, animated title cards, social overlays, captioned talking-head videos, audio-reactive visuals, and shader transitions using HyperFrames.

    327 GitHub stars~3.6k tokensUpdated 1 mo ago
    Auto-check passed
  • Powerpoint

    johnson7788/MultiUserClaw

    Create, read, edit .pptx decks, slides, notes, templates. An agent skill from johnson7788/MultiUserClaw.

    327 GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Computer Use

    johnson7788/MultiUserClaw

    Drive the user's desktop in the background — clicking, typing, scrolling, dragging — without stealing the cursor, keyboard focus, or switching virtual desktops / Spaces.

    327 GitHub starsUsed in 1 repo~2.8k tokens
    Auto-check: warnings
  • Hermes Agent Skill Authoring

    johnson7788/MultiUserClaw

    Author in-repo SKILL.md: frontmatter, validator, structure, and writing-quality principles.

    327 GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Hermes S6 Container Supervision

    johnson7788/MultiUserClaw

    Modify, debug, or extend the s6-overlay supervision tree inside the Hermes Agent Docker image — adding new services, debugging profile gateways, understanding the Architecture B main-program pattern.

    327 GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check: notes
  • Plan

    johnson7788/MultiUserClaw

    Plan mode: write an actionable markdown plan to .hermes/plans/, no execution.

    327 GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Osint Investigation

What does Osint Investigation do?

Public-records OSINT investigation framework — SEC EDGAR filings, USAspending contracts, Senate lobbying, OFAC sanctions, ICIJ offshore leaks, NYC property records (ACRIS), OpenCorporates…. Osint Investigation is an agent skill from johnson7788/MultiUserClaw. Public-records OSINT investigation framework — SEC EDGAR filings, USAspending contracts, Senate lobbying, OFAC sanctions, ICIJ offshore leaks, NYC property records (ACRIS), OpenCorporates registries, CourtListener court records, Wayback Machine archives, Wikipedia + Wikidata, GDELT news monitoring.

When should I use Osint Investigation?

Osint Investigation fits situations like: tasks that involve OSINT.

How do I install Osint Investigation in Claude Code?

Run `npx skills add johnson7788/MultiUserClaw --skill osint-investigation -a claude-code`. Or copy the skill folder (hermes-agent/optional-skills/research/osint-investigation in johnson7788/MultiUserClaw) into .claude/skills/osint-investigation in your project. Claude Code loads it when a task matches its description.

How do I install Osint Investigation in Codex?

Run `npx skills add johnson7788/MultiUserClaw --skill osint-investigation -a codex`. Or copy the skill folder (hermes-agent/optional-skills/research/osint-investigation in johnson7788/MultiUserClaw) into .agents/skills/osint-investigation in your project. Codex loads it when a task matches its description.

Can I use Osint Investigation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add johnson7788/MultiUserClaw --skill osint-investigation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/osint-investigation, .gemini/skills/osint-investigation, .github/skills/osint-investigation and .opencode/skills/osint-investigation in your project.

What does Osint Investigation need to run?

Going by SKILL.md and its folder, Osint Investigation needs Python for the scripts in its folder, the command-line tools its instructions call (python3) and credentials named OPENCORPORATES_API_TOKEN, SENATE_LDA_TOKEN, COURTLISTENER_TOKEN and DEMO_KEY. Our summary lists: Python 3; A credential in DEMO_KEY; A credential in OPENCORPORATES_API_TOKEN.

Does Osint Investigation access the network?

SKILL.md names 1 domain. As links in the text: fec.gov. This is read from the text; nothing was executed.

Is Osint Investigation safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Osint Investigation use?

Osint Investigation is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Osint Investigation use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 10k tokens, read only when the agent opens those files.

What are the alternatives to Osint Investigation?

Skills that share tags, products or a category with Osint Investigation: Domain Intel (Tommy-yw/RunbookHermes, 546 stars), Implementing Stix Taxii Feed Integration (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Automating Ioc Enrichment (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Building Adversary Infrastructure Tracking System (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Osint Investigation?

johnson7788 (a GitHub user) maintains it in johnson7788/MultiUserClaw, which has 327 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on August 13, 2026.

Source: johnson7788/MultiUserClaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.