Osint Investigation
affaan-m/ECC
Sparse-clue OSINT investigation methodology for extracting overlooked leads, connecting fragmented evidence, and testing explanations across sources.
Provides open source intelligence techniques for CTF challenges.
$ npx skills add ljagiello/ctf-skills --skill ctf-osint -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ljagiello/ctf-skills ctf-osint --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ljagiello/ctf-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/ctf-osint .claude/skills/ctf-osint && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "ctf-osint" agent skill from https://github.com/ljagiello/ctf-skills/tree/main/ctf-osint into .claude/skills/ctf-osint/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ctf-osint", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ljagiello/ctf-skills/tree/main/ctf-osintType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ljagiello/ctf-skills --skill ctf-osint -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ljagiello/ctf-skills ctf-osint --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ljagiello/ctf-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/ctf-osint .agents/skills/ctf-osint && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "ctf-osint" agent skill from https://github.com/ljagiello/ctf-skills/tree/main/ctf-osint into .agents/skills/ctf-osint/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ctf-osint", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ljagiello/ctf-skills --skill ctf-osint -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ljagiello/ctf-skills ctf-osint --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ljagiello/ctf-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/ctf-osint .cursor/skills/ctf-osint && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "ctf-osint" agent skill from https://github.com/ljagiello/ctf-skills/tree/main/ctf-osint into .cursor/skills/ctf-osint/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ctf-osint", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ljagiello/ctf-skills.git --path ctf-osint--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ljagiello/ctf-skills --skill ctf-osint -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ljagiello/ctf-skills ctf-osint --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ljagiello/ctf-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/ctf-osint .gemini/skills/ctf-osint && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "ctf-osint" agent skill from https://github.com/ljagiello/ctf-skills/tree/main/ctf-osint into .gemini/skills/ctf-osint/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ctf-osint", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ljagiello/ctf-skills ctf-osintInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ljagiello/ctf-skills --skill ctf-osint -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ljagiello/ctf-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/ctf-osint .github/skills/ctf-osint && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "ctf-osint" agent skill from https://github.com/ljagiello/ctf-skills/tree/main/ctf-osint into .github/skills/ctf-osint/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ctf-osint", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ljagiello/ctf-skills --skill ctf-osint -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ljagiello/ctf-skills ctf-osint --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ljagiello/ctf-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/ctf-osint .opencode/skills/ctf-osint && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "ctf-osint" agent skill from https://github.com/ljagiello/ctf-skills/tree/main/ctf-osint into .opencode/skills/ctf-osint/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ctf-osint", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
ctf-osintProvides open source intelligence techniques for CTF challenges.
Ctf Osint is an agent skill from ljagiello/ctf-skills. Provides open source intelligence techniques for CTF challenges. Use when gathering information from public sources, social media, geolocation, DNS records, username enumeration, reverse image search, Google dorking, Wayback Machine, Tor relays, FEC filings, or identifying unknown data like hashes and coordinates.
Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files (for example `geolocation-and-media.md`, `social-media.md` and `web-and-dns.md`). Compatibility notes: Requires filesystem-based agent (Claude Code or similar) with bash, Python 3, and internet access for OSINT lookups.
It sits in Security, covering Capture the flag and OSINT. The repository describes itself as: Agent skills for solving CTF challenges - web exploitation, binary pwn, crypto, reverse engineering, forensics, OSINT, and more. The licence is MIT.
Read from SKILL.md and the folder at commit c332c7b. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
BashReadWriteEditGlobGrepTaskWebFetchWebSearchFrom allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
curlpipaptbrewghFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
whatsmyname.appx.commetrics.torproject.orgweb.archive.orgip-api.comAlso links to:
namechk.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Requires filesystem-based agent (Claude Code or similar) with bash, Python 3, and internet access for OSINT lookups.
From compatibility in the SKILL.md frontmatter.
Ctf Osint loads about 2.3k tokens when it runs. Until then it costs about 81 tokens; SKILL.md has 775 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
allowed-tools: Bash, Read, Write, Edit, Glob, Grep, Task, WebFetch, WebSearchAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from ljagiello/ctf-skills at commit c332c7b, republished under its MIT licence (© ljagiello). 775 words, ~2,313 tokens.
.claude/skills/ctf-osint/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Quick reference for OSINT CTF challenges. Each technique has a one-liner here; see supporting files for full details.
Python packages (all platforms):
pip install shodan PillowLinux (apt):
apt install whois dnsutils nmap libimage-exiftool-perl imagemagick curlmacOS (Homebrew):
brew install whois bind nmap exiftool imagemagick curl/ctf-forensics./ctf-web./ctf-malware.# DNS recon
dig -t any target.com
dig -t txt target.com
dig axfr @ns.target.com target.com
whois target.com
# Image metadata
exiftool image.jpg
identify -verbose image.jpg | head -30
# Web archive
curl "https://web.archive.org/web/20230101*/target.com"
# Username lookup
curl -s "https://whatsmyname.app/api/lookup?username=<user>"
# Shodan
shodan search "hostname:target.com"
shodan host <ip>https://x.com/i/user/<id> works even after renames.(id >> 22) + 1288834974657 = Unix ms.curl -sI for x-tumblr-user header. Avatar at /avatar/512. See social-media.md.XXXX+XXX (chars: 23456789CFGHJMPQRVWX). Drop a pin on Google Maps → Plus Code appears in details. Free, no API key needed. See geolocation-and-media.md.exiftool image.jpg # EXIF data
pdfinfo document.pdf # PDF metadata
mediainfo video.mp4 # Video metadatasite:example.com filetype:pdf
intitle:"index of" passwordImage TBS filters: Append &tbs=itp:face to Google Image URLs to filter for faces only (strips logos/banners). See web-and-dns.md.
/export?format=csv, /pub, /gviz/tq?tqx=out:csv, /htmlview. See web-and-dns.md.dig -t txt subdomain.ctf.domain.com
dig axfr @ns.domain.com domain.com # Zone transferAlways check TXT, CNAME, MX for CTF domains. See web-and-dns.md.
https://metrics.torproject.org/rs.html#simple/<FINGERPRINT> -- check family, sort by "first seen". See web-and-dns.md.gh api. See web-and-dns.md./start, answer verification questions. See web-and-dns.md.curl "http://ip-api.com/json/103.150.68.150"Pattern: Visually-identical Unicode characters from different blocks (Cyrillic, Greek, Math) encode binary data in social media posts. ASCII = 0, homoglyph = 1. Group bits into bytes for flag. See social-media.md.
No auth needed. Endpoints: public.api.bsky.app/xrpc/app.bsky.feed.searchPosts?q=..., app.bsky.actor.searchActors, app.bsky.feed.getAuthorFeed. Check all replies to official posts. See social-media.md.
Pattern: Port appears open on a standard service port (22/SSH, 80/HTTP) but runs a fake service. nmap -sV or nc host port reveals the flag in the banner. Never trust port numbers alone -- always fingerprint the service. See web-and-dns.md.
Search Shodan by SSH host key fingerprint to identify servers: shodan search "fingerprint:AA:BB:CC:...". See web-and-dns.md.
Lookup usernames across gaming platforms (Steam, Xbox, PSN, MMOs) for character profiles, activity, and linked accounts. See social-media.md.
© ljagiello, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files in ctf-osint of ljagiello/ctf-skills.
Open the folder on GitHubat commit c332c7b
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in ljagiello/ctf-skills, which our catalogue first saw on October 7, 2026.
Ctf Osint next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Ctf Osint this skillljagiello/ctf-skills | 3.4k | 1 repos | ~2.3k | Automated safety check: Notes | MIT | |
| Osint Investigationaffaan-m/ECC | 276k | — | ~5.7k | Automated safety check: Pass | CC-BY-SA-4.0 | |
| Ctf Osintwgpsec/AboutSecurity | 1.8k | — | ~530 | Automated safety check: Pass | None | |
| Metabigor OSINT Reconj3ssie/metabigor | 1.9k | — | ~2.4k | Automated safety check: Pass | MIT | |
| Helloctf SkillProbiusOfficial/Hello-CTF | 4.2k | — | ~387 | Automated safety check: Pass | GPL-3.0 | |
| ShadowBroker Intelligence ClientBigBodyCobain/Shadowbroker | 11k | — | ~8.9k | Automated safety check: Warn | AGPL-3.0 |
affaan-m/ECC
Sparse-clue OSINT investigation methodology for extracting overlooked leads, connecting fragmented evidence, and testing explanations across sources.
wgpsec/AboutSecurity
CTF 开源情报(OSINT)技术。当挑战要求从公开信息中找线索——如给定用户名/邮箱追踪身份、给定照片进行地理定位、从历史网页快照中恢复数据时使用。覆盖社交媒体调查、Google Dorking、反向图片搜索、Wayback Machine、DNS 侦察、Tor 中继查询、元数据提取
j3ssie/metabigor
Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys.
ProbiusOfficial/Hello-CTF
Hello CTF 技能树 —— 基于国内 CTF 竞赛体系整理的全方向攻防知识库。当用户在学习 CTF、备战比赛、解赛题(Web / Crypto / Misc / Pwn / Reverse / AI / 云安全 / 数据安全 / 区块链 / 工控 / 物联网 / 应急响应 / 渗透测试)需要定位知识点、查询利用手法或规划学习路线时使用。也适用于按知识域出题、查漏补缺。
BigBodyCobain/Shadowbroker
Lets an agent query a ShadowBroker OSINT platform for tracked flights, ships, satellites and news, and place its findings on the map as intel pins.
shoyann/RZK-The-Hunter
Ethical, evidence-first OSINT planning, tool selection, verification, monitoring, reporting, and guarded official wanted/fugitive-person location intelligence using a structured catalog adapted from…
ljagiello/ctf-skills
Provides malware analysis and network traffic techniques for CTF challenges.
ljagiello/ctf-skills
Solves CTF challenges by performing first-pass triage, identifying the dominant category, and routing execution to the right specialized ctf- skill.
ljagiello/ctf-skills
Provides cryptography attack techniques for CTF challenges. An agent skill from ljagiello/ctf-skills.
ljagiello/ctf-skills
Generates a single standardized submission-style CTF writeup for competition handoff and organizer review.
ljagiello/ctf-skills
Provides digital forensics and signal analysis techniques for CTF challenges.
Categories
Provides open source intelligence techniques for CTF challenges. Ctf Osint is an agent skill from ljagiello/ctf-skills. Provides open source intelligence techniques for CTF challenges.
Ctf Osint fits situations like: gathering information from public sources; username enumeration; reverse image search; wayback Machine.
Run `npx skills add ljagiello/ctf-skills --skill ctf-osint -a claude-code`. Or copy the skill folder (ctf-osint in ljagiello/ctf-skills) into .claude/skills/ctf-osint in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ljagiello/ctf-skills --skill ctf-osint -a codex`. Or copy the skill folder (ctf-osint in ljagiello/ctf-skills) into .agents/skills/ctf-osint in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ljagiello/ctf-skills --skill ctf-osint -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ctf-osint, .gemini/skills/ctf-osint, .github/skills/ctf-osint and .opencode/skills/ctf-osint in your project.
Going by SKILL.md and its folder, Ctf Osint needs the command-line tools its instructions call (curl, pip, apt, brew and gh). Our summary lists: Python 3. Its frontmatter pre-approves these tools: Bash, Read, Write, Edit, Glob, Grep, Task, WebFetch, WebSearch. Compatibility (from SKILL.md): Requires filesystem-based agent (Claude Code or similar) with bash, Python 3, and internet access for OSINT lookups..
SKILL.md names 6 domains. In commands or code: whatsmyname.app, x.com, metrics.torproject.org, web.archive.org and ip-api.com; the agent is likely to contact these when it follows the instructions. As links in the text: namechk.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Ctf Osint is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.3k tokens (SKILL.md is roughly 9.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Ctf Osint: Osint Investigation (affaan-m/ECC, 276k stars), Ctf Osint (wgpsec/AboutSecurity, 1.8k stars), Metabigor OSINT Recon (j3ssie/metabigor, 1.9k stars) and Helloctf Skill (ProbiusOfficial/Hello-CTF, 4.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ljagiello (a GitHub user) maintains it in ljagiello/ctf-skills, which has 3,421 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on September 13, 2026.
Source: ljagiello/ctf-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.