Agent skill

Ctf Osint

by ljagiello in ljagiello/ctf-skills

Provides open source intelligence techniques for CTF challenges.

MITAuto-check: notesSecurity

Install Ctf Osint

skills CLI
$ npx skills add ljagiello/ctf-skills --skill ctf-osint -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ljagiello/ctf-skills ctf-osint --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ljagiello/ctf-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/ctf-osint .claude/skills/ctf-osint && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ctf-osint
GitHub stars
3.4k
Used in
1 other repo
Token cost
~2.3k tokens
SKILL.md length
775 words
Files
4
Skills in repo
6
Repo updated
First seen
Licence
MIT

At a glance

Provides open source intelligence techniques for CTF challenges.

  • Gathering information from public sources
  • SKILL.md covers Prerequisites, Additional Resources, When to Pivot and Quick Start Commands, plus 23 more sections
  • Calls curl, pip and apt; reaches whatsmyname.app and x.com
  • Username enumeration

What it does

Ctf Osint is an agent skill from ljagiello/ctf-skills. Provides open source intelligence techniques for CTF challenges. Use when gathering information from public sources, social media, geolocation, DNS records, username enumeration, reverse image search, Google dorking, Wayback Machine, Tor relays, FEC filings, or identifying unknown data like hashes and coordinates.

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files (for example `geolocation-and-media.md`, `social-media.md` and `web-and-dns.md`). Compatibility notes: Requires filesystem-based agent (Claude Code or similar) with bash, Python 3, and internet access for OSINT lookups.

It sits in Security, covering Capture the flag and OSINT. The repository describes itself as: Agent skills for solving CTF challenges - web exploitation, binary pwn, crypto, reverse engineering, forensics, OSINT, and more. The licence is MIT.

When your agent uses it

  • Gathering information from public sources
  • Username enumeration
  • Reverse image search
  • Wayback Machine

Example prompts

  • “Use the ctf-osint skill to provide open source intelligence techniques for CTF challenges”
  • “/ctf-osint”

Requirements

  • Python 3
  • Compatibility (from SKILL.md): Requires filesystem-based agent (Claude Code or similar) with bash, Python 3, and internet access for OSINT lookups.
  • Pre-approved tools (allowed-tools): Bash, Read, Write, Edit, Glob, Grep, Task, WebFetch, WebSearch

What it can do on your machine

Read from SKILL.md and the folder at commit c332c7b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read
    • Write
    • Edit
    • Glob
    • Grep
    • Task
    • WebFetch
    • WebSearch

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • pip
    • apt
    • brew
    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • whatsmyname.app
    • x.com
    • metrics.torproject.org
    • web.archive.org
    • ip-api.com

    Also links to:

    • namechk.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires filesystem-based agent (Claude Code or similar) with bash, Python 3, and internet access for OSINT lookups.

    From compatibility in the SKILL.md frontmatter.

Context cost

Ctf Osint loads about 2.3k tokens when it runs. Until then it costs about 81 tokens; SKILL.md has 775 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~81
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read, Write, Edit, Glob, Grep, Task, WebFetch, WebSearch

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ljagiello/ctf-skills at commit c332c7b, republished under its MIT licence (© ljagiello). 775 words, ~2,313 tokens.

Download SKILL.mdSave it as .claude/skills/ctf-osint/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
ctf-osint
description
Provides open source intelligence techniques for CTF challenges. Use when gathering information from public sources, social media, geolocation, DNS records, username enumeration, reverse image search, Google dorking, Wayback Machine, Tor relays, FEC filings, or identifying unknown data like hashes and coordinates.
allowed-tools
Bash, Read, Write, Edit, Glob, Grep, Task, WebFetch, WebSearch
compatibility
Requires filesystem-based agent (Claude Code or similar) with bash, Python 3, and internet access for OSINT lookups.
license
MIT
metadata.user-invocable
false

CTF OSINT

Quick reference for OSINT CTF challenges. Each technique has a one-liner here; see supporting files for full details.

Prerequisites

Python packages (all platforms):

bash
pip install shodan Pillow

Linux (apt):

bash
apt install whois dnsutils nmap libimage-exiftool-perl imagemagick curl

macOS (Homebrew):

bash
brew install whois bind nmap exiftool imagemagick curl

Additional Resources

  • social-media.md - Twitter/X (user IDs, Snowflake timestamps, Nitter, memory.lol, Wayback CDX), Tumblr (blog checks, post JSON, avatars), BlueSky search + API, Unicode homoglyph steganography, Discord API, username OSINT (namechk, whatsmyname, Osint Industries), username metadata mining (postal codes), platform false positives, multi-platform chains, Strava fitness route OSINT
  • geolocation-and-media.md - Image analysis, reverse image search (including Baidu for China), Google Lens cropped region search, reflected/mirrored text reading, geolocation techniques (railroad signs, infrastructure maps, MGRS), Google Plus Codes, EXIF/metadata, hardware identification, newspaper archives, IP geolocation, Google Street View panorama matching, What3Words micro-landmark matching, Google Maps crowd-sourced photo verification, Overpass Turbo spatial queries, music-themed landmark geolocation with key encoding
  • web-and-dns.md - Google dorking (including TBS image filters), Google Docs/Sheets enumeration, DNS recon (TXT, zone transfers), Wayback Machine, FEC research, Tor relay lookups, GitHub repository analysis, Telegram bot investigation, WHOIS investigation (reverse WHOIS, historical WHOIS, IP/ASN lookup), fake service banner detection via nmap fingerprinting

When to Pivot

  • If you already have the files or packets locally and now need extraction or carving, switch to /ctf-forensics.
  • If the task becomes active exploitation of a live HTTP service, switch to /ctf-web.
  • If you uncover malware samples, beacons, or suspicious binaries during attribution, switch to /ctf-malware.

Quick Start Commands

bash
# DNS recon
dig -t any target.com
dig -t txt target.com
dig axfr @ns.target.com target.com
whois target.com

# Image metadata
exiftool image.jpg
identify -verbose image.jpg | head -30

# Web archive
curl "https://web.archive.org/web/20230101*/target.com"

# Username lookup
curl -s "https://whatsmyname.app/api/lookup?username=<user>"

# Shodan
shodan search "hostname:target.com"
shodan host <ip>

String Identification

  • 40 hex chars -> SHA-1 (Tor fingerprint)
  • 64 hex chars -> SHA-256
  • 32 hex chars -> MD5

Twitter/X Account Tracking

  • Persistent numeric User ID: https://x.com/i/user/<id> works even after renames.
  • Snowflake timestamps: (id >> 22) + 1288834974657 = Unix ms.
  • Wayback CDX, Nitter, memory.lol for historical data. See social-media.md.

Tumblr Investigation

  • Blog check: curl -sI for x-tumblr-user header. Avatar at /avatar/512. See social-media.md.

Username OSINT

  • Google Lens (crop to region of interest), Google Images, TinEye, Yandex (faces). Check corners for visual stego. Twitter strips EXIF. See geolocation-and-media.md.
  • Cropped region search: Isolate distinctive elements (shop signs, building facades) and search via Google Lens for better results than full-scene search. See geolocation-and-media.md.
  • Reflected text: Flip mirrored/reflected text (water, glass) horizontally; search partial text with quoted strings. See geolocation-and-media.md.

Geolocation

  • Railroad signs, infrastructure maps (OpenRailwayMap, OpenInfraMap), process of elimination. See geolocation-and-media.md.
  • Street View panorama matching: Feature extraction + multi-metric image similarity ranking against candidate panoramas. Useful when challenge image is a crop of a Street View photo. See geolocation-and-media.md.
  • Road sign OCR: Extract text from directional signs (town names, route numbers) to pinpoint road corridors. Driving side + sign style + script identify the country. See geolocation-and-media.md.
  • Architecture + brand identification: Post-Soviet concrete = Russia/CIS; named businesses → search locations/branches → cross-reference with coastline/terrain. See geolocation-and-media.md.
  • Music-themed landmark geolocation: Multiple images of music-related landmarks worldwide; each yields a piano key number encoding one flag character. Identify all locations first, then decode the key sequence. See geolocation-and-media.md.
Show full SKILL.md (300 more words)Show less

MGRS Coordinates

Google Plus Codes

  • Format XXXX+XXX (chars: 23456789CFGHJMPQRVWX). Drop a pin on Google Maps → Plus Code appears in details. Free, no API key needed. See geolocation-and-media.md.

Metadata Extraction

bash
exiftool image.jpg           # EXIF data
pdfinfo document.pdf         # PDF metadata
mediainfo video.mp4          # Video metadata

Google Dorking

text
site:example.com filetype:pdf
intitle:"index of" password

Image TBS filters: Append &tbs=itp:face to Google Image URLs to filter for faces only (strips logos/banners). See web-and-dns.md.

Google Docs/Sheets

  • Try /export?format=csv, /pub, /gviz/tq?tqx=out:csv, /htmlview. See web-and-dns.md.

DNS Reconnaissance

bash
dig -t txt subdomain.ctf.domain.com
dig axfr @ns.domain.com domain.com  # Zone transfer

Always check TXT, CNAME, MX for CTF domains. See web-and-dns.md.

Tor Relay Lookups

  • https://metrics.torproject.org/rs.html#simple/<FINGERPRINT> -- check family, sort by "first seen". See web-and-dns.md.

GitHub Repository Analysis

  • Check issue comments, PR reviews, commit messages, wiki edits via gh api. See web-and-dns.md.

Telegram Bot Investigation

  • Find bot references in browser history, interact via /start, answer verification questions. See web-and-dns.md.

FEC Political Donation Research

  • FEC.gov for committee receipts; 501(c)(4) orgs obscure original funders. See web-and-dns.md.

IP Geolocation

bash
curl "http://ip-api.com/json/103.150.68.150"

See geolocation-and-media.md.

Unicode Homoglyph Steganography

Pattern: Visually-identical Unicode characters from different blocks (Cyrillic, Greek, Math) encode binary data in social media posts. ASCII = 0, homoglyph = 1. Group bits into bytes for flag. See social-media.md.

BlueSky Public API

No auth needed. Endpoints: public.api.bsky.app/xrpc/app.bsky.feed.searchPosts?q=..., app.bsky.actor.searchActors, app.bsky.feed.getAuthorFeed. Check all replies to official posts. See social-media.md.

Fake Service Banner Detection

Pattern: Port appears open on a standard service port (22/SSH, 80/HTTP) but runs a fake service. nmap -sV or nc host port reveals the flag in the banner. Never trust port numbers alone -- always fingerprint the service. See web-and-dns.md.

Shodan SSH Fingerprint Lookup

Search Shodan by SSH host key fingerprint to identify servers: shodan search "fingerprint:AA:BB:CC:...". See web-and-dns.md.

Gaming Platform OSINT

Lookup usernames across gaming platforms (Steam, Xbox, PSN, MMOs) for character profiles, activity, and linked accounts. See social-media.md.

Resources

  • Shodan - Internet-connected devices
  • Censys - Certificate and host search
  • VirusTotal - File/URL reputation
  • WHOIS - Domain registration
  • Wayback Machine - Historical snapshots

© ljagiello, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files in ctf-osint of ljagiello/ctf-skills.

  • SKILL.md
  • geolocation-and-media.md
  • social-media.md
  • web-and-dns.md

Open the folder on GitHubat commit c332c7b

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in ljagiello/ctf-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Ctf Osint next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ctf Osint compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ctf Osint this skillljagiello/ctf-skills3.4k1 repos~2.3kAutomated safety check: NotesMIT
Osint Investigationaffaan-m/ECC276k—~5.7kAutomated safety check: PassCC-BY-SA-4.0
Ctf Osintwgpsec/AboutSecurity1.8k—~530Automated safety check: PassNone
Metabigor OSINT Reconj3ssie/metabigor1.9k—~2.4kAutomated safety check: PassMIT
Helloctf SkillProbiusOfficial/Hello-CTF4.2k—~387Automated safety check: PassGPL-3.0
ShadowBroker Intelligence ClientBigBodyCobain/Shadowbroker11k—~8.9kAutomated safety check: WarnAGPL-3.0

Similar skills

  • Sparse-clue OSINT investigation methodology for extracting overlooked leads, connecting fragmented evidence, and testing explanations across sources.

    276k GitHub stars~5.7k tokensUpdated yesterday
    SecurityAuto-check passed
  • Ctf Osint

    wgpsec/AboutSecurity

    CTF 开源情报(OSINT)技术。当挑战要求从公开信息中找线索——如给定用户名/邮箱追踪身份、给定照片进行地理定位、从历史网页快照中恢复数据时使用。覆盖社交媒体调查、Google Dorking、反向图片搜索、Wayback Machine、DNS 侦察、Tor 中继查询、元数据提取

    1.8k GitHub stars~530 tokensUpdated yesterday
    SecurityAuto-check passed
  • Metabigor OSINT Recon

    j3ssie/metabigor

    Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys.

    1.9k GitHub stars~2.4k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Helloctf Skill

    ProbiusOfficial/Hello-CTF

    Hello CTF 技能树 —— 基于国内 CTF 竞赛体系整理的全方向攻防知识库。当用户在学习 CTF、备战比赛、解赛题(Web / Crypto / Misc / Pwn / Reverse / AI / 云安全 / 数据安全 / 区块链 / 工控 / 物联网 / 应急响应 / 渗透测试)需要定位知识点、查询利用手法或规划学习路线时使用。也适用于按知识域出题、查漏补缺。

    4.2k GitHub stars~387 tokensUpdated today
    SecurityAuto-check passed
  • ShadowBroker Intelligence Client

    BigBodyCobain/Shadowbroker

    Lets an agent query a ShadowBroker OSINT platform for tracked flights, ships, satellites and news, and place its findings on the map as intel pins.

    11k GitHub stars~8.9k tokensUpdated today
    SecurityAuto-check: warnings
  • Awesome Osint Operator

    shoyann/RZK-The-Hunter

    Ethical, evidence-first OSINT planning, tool selection, verification, monitoring, reporting, and guarded official wanted/fugitive-person location intelligence using a structured catalog adapted from…

    141 GitHub stars~4.8k tokensUpdated 2 days ago
    SecurityAuto-check passed

More from ljagiello/ctf-skills

  • Ctf Malware

    ljagiello/ctf-skills

    Provides malware analysis and network traffic techniques for CTF challenges.

    3.4k GitHub stars~2.1k tokensUpdated 27 days ago
    Auto-check: notes
  • Solve Challenge

    ljagiello/ctf-skills

    Solves CTF challenges by performing first-pass triage, identifying the dominant category, and routing execution to the right specialized ctf- skill.

    3.4k GitHub stars~2.3k tokensUpdated 27 days ago
    Auto-check: notes
  • Ctf Crypto

    ljagiello/ctf-skills

    Provides cryptography attack techniques for CTF challenges. An agent skill from ljagiello/ctf-skills.

    3.4k GitHub stars~11k tokensUpdated 27 days ago
    Auto-check: notes
  • Ctf Writeup

    ljagiello/ctf-skills

    Generates a single standardized submission-style CTF writeup for competition handoff and organizer review.

    3.4k GitHub stars~1.2k tokensUpdated 27 days ago
    Auto-check: notes
  • Ctf Forensics

    ljagiello/ctf-skills

    Provides digital forensics and signal analysis techniques for CTF challenges.

    3.4k GitHub stars~9.2k tokensUpdated 27 days ago
    Auto-check: warnings

Categories

Questions about Ctf Osint

What does Ctf Osint do?

Provides open source intelligence techniques for CTF challenges. Ctf Osint is an agent skill from ljagiello/ctf-skills. Provides open source intelligence techniques for CTF challenges.

When should I use Ctf Osint?

Ctf Osint fits situations like: gathering information from public sources; username enumeration; reverse image search; wayback Machine.

How do I install Ctf Osint in Claude Code?

Run `npx skills add ljagiello/ctf-skills --skill ctf-osint -a claude-code`. Or copy the skill folder (ctf-osint in ljagiello/ctf-skills) into .claude/skills/ctf-osint in your project. Claude Code loads it when a task matches its description.

How do I install Ctf Osint in Codex?

Run `npx skills add ljagiello/ctf-skills --skill ctf-osint -a codex`. Or copy the skill folder (ctf-osint in ljagiello/ctf-skills) into .agents/skills/ctf-osint in your project. Codex loads it when a task matches its description.

Can I use Ctf Osint in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ljagiello/ctf-skills --skill ctf-osint -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ctf-osint, .gemini/skills/ctf-osint, .github/skills/ctf-osint and .opencode/skills/ctf-osint in your project.

What does Ctf Osint need to run?

Going by SKILL.md and its folder, Ctf Osint needs the command-line tools its instructions call (curl, pip, apt, brew and gh). Our summary lists: Python 3. Its frontmatter pre-approves these tools: Bash, Read, Write, Edit, Glob, Grep, Task, WebFetch, WebSearch. Compatibility (from SKILL.md): Requires filesystem-based agent (Claude Code or similar) with bash, Python 3, and internet access for OSINT lookups..

Does Ctf Osint access the network?

SKILL.md names 6 domains. In commands or code: whatsmyname.app, x.com, metrics.torproject.org, web.archive.org and ip-api.com; the agent is likely to contact these when it follows the instructions. As links in the text: namechk.com. This is read from the text; nothing was executed.

Is Ctf Osint safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Ctf Osint use?

Ctf Osint is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ctf Osint use?

About 2.3k tokens (SKILL.md is roughly 9.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ctf Osint?

Skills that share tags, products or a category with Ctf Osint: Osint Investigation (affaan-m/ECC, 276k stars), Ctf Osint (wgpsec/AboutSecurity, 1.8k stars), Metabigor OSINT Recon (j3ssie/metabigor, 1.9k stars) and Helloctf Skill (ProbiusOfficial/Hello-CTF, 4.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ctf Osint?

ljagiello (a GitHub user) maintains it in ljagiello/ctf-skills, which has 3,421 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on September 13, 2026.

Source: ljagiello/ctf-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.