Agent skill

Performing AI Driven Osint Correlation

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Use AI/LLM-based reasoning with Sherlock, theHarvester, and SpiderFoot to correlate OSINT findings—usernames, emails, social profiles, domain records, breach databases, and dark-web mentions—into…

Apache-2.0Auto-check passedSecurity

Install Performing AI Driven Osint Correlation

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-ai-driven-osint-correlation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills performing-ai-driven-osint-correlation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/performing-ai-driven-osint-correlation .claude/skills/performing-ai-driven-osint-correlation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
performing-ai-driven-osint-correlation
GitHub stars
34k
Token cost
~3.6k tokens
SKILL.md length
670 words
Files
4 (incl. scripts, references)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Use AI/LLM-based reasoning with Sherlock, theHarvester, and SpiderFoot to correlate OSINT findings—usernames, emails, social profiles, domain records, breach databases, and dark-web mentions—into…

  • Works in 4 steps: Multi-Source OSINT Collection → Data Normalization → AI-Driven Correlation → …
  • Raw OSINT data from multiple sources needs merging into one target profile
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 4 more sections
  • Runs Python scripts from its folder; calls python3, curl and pip; reaches haveibeenpwned.com; needs HIBP_KEY and OPENAI_API_KEY

What it does

Performing AI Driven Osint Correlation is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Use AI/LLM-based reasoning with Sherlock, theHarvester, and SpiderFoot to correlate OSINT findings—usernames, emails, social profiles, domain records, breach databases, and dark-web mentions—into unified, confidence-scored intelligence profiles with link analysis. Use when raw OSINT data from multiple sources needs merging into one target profile or resolving identity linkage across platforms.

Its SKILL.md is about 3.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).

It sits in Security, covering OSINT. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Raw OSINT data from multiple sources needs merging into one target profile
  • Resolving identity linkage across platforms

Example prompts

  • “/performing-ai-driven-osint-correlation”

Requirements

  • Python 3
  • A credential in HIBP_KEY
  • A credential in OPENAI_API_KEY

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Multi-Source OSINT Collection
  2. Data Normalization
  3. AI-Driven Correlation
  4. Reporting and Visualization

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3
    • curl
    • pip
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • haveibeenpwned.com

    Also links to:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • HIBP_KEY
    • OPENAI_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Performing AI Driven Osint Correlation loads about 3.6k tokens when it runs, and up to ~4.9k if it reads all its reference files. Until then it costs about 109 tokens; SKILL.md has 670 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~109
When it runs · the whole SKILL.md, loaded when a task matches
~3.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 670 words, ~3,644 tokens.

Download SKILL.mdSave it as .claude/skills/performing-ai-driven-osint-correlation/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
performing-ai-driven-osint-correlation
description
Use AI/LLM-based reasoning with Sherlock, theHarvester, and SpiderFoot to correlate OSINT findings—usernames, emails, social profiles, domain records, breach databases, and dark-web mentions—into unified, confidence-scored intelligence profiles with link analysis. Use when raw OSINT data from multiple sources needs merging into one target profile or resolving identity linkage across platforms.
domain
cybersecurity
subdomain
threat-intelligence
tags
osint, ai-correlation, threat-intelligence, reconnaissance, link-analysis, target-profiling, sherlock, theharvester, spiderfoot, maltego
version
1.0
author
juliosuas
license
Apache-2.0
atlas_techniques
AML.T0051, AML.T0054, AML.T0056
nist_ai_rmf
MEASURE-2.7, MEASURE-2.5, GOVERN-6.1, MAP-5.1
d3fend_techniques
Identifier Analysis, URL Analysis, Identifier Reputation Analysis, User Behavior Analysis, Content Validation
nist_csf
ID.RA-01, ID.RA-05, DE.CM-01, DE.AE-02

Performing AI-Driven OSINT Correlation

When to Use

  • You have collected raw OSINT data from multiple tools and sources but need to identify connections, contradictions, and patterns across them.
  • You need to build a unified intelligence profile for a target entity (person, organization, or infrastructure) from fragmented data.
  • Traditional manual correlation is too slow or error-prone for the volume of data collected.
  • You want confidence-scored assessments of identity linkage across platforms rather than simple keyword matching.

Prerequisites

  • Python 3.10+ with requests, json, and csv libraries
  • Sherlock installed (pip install sherlock-project)
  • theHarvester installed (pip install theHarvester)
  • SpiderFoot 4.0+ running on localhost:5001
  • Access to an LLM API (OpenAI, Anthropic, or local model via Ollama)
  • Optional: Maltego CE for graph visualization of correlation results
  • Optional: API keys for Shodan, VirusTotal, HaveIBeenPwned, Hunter.io

Workflow

  • Obtain documented written authorization before any investigation
  • Establish lawful basis for data processing (law enforcement, corporate policy, etc.)
  • Define PII retention limits and data handling procedures
  • Comply with local privacy regulations (GDPR, CCPA, etc.)
Phase 1 — Multi-Source OSINT Collection
  1. Create the working directory for all OSINT outputs:

    bash
    mkdir -p /tmp/osint
  2. Enumerate usernames across platforms with Sherlock:

    bash
    sherlock "targetusername" --output /tmp/osint/sherlock-results.txt --csv
  3. Harvest emails, subdomains, and hosts with theHarvester:

    bash
    theHarvester -d targetdomain.com -b all -f /tmp/osint/harvester-results.json
  4. Run a SpiderFoot passive scan via REST API:

    bash
    curl -s http://localhost:5001/api/scan/start \
      -d "scanname=target-recon&scantarget=targetdomain.com&usecase=passive" \
      | jq '.scanid'
  5. Export SpiderFoot results when scan completes:

    bash
    SCAN_ID="<scanid_from_step_3>"
    curl -s "http://localhost:5001/api/scan/${SCAN_ID}/results?type=all" \
      -o /tmp/osint/spiderfoot-results.json
  6. Query breach databases for email exposure (example with HIBP API):

    bash
    curl -s -H "hibp-api-key: ${HIBP_KEY}" \
      -H "User-Agent: OSINT-Correlation-Skill" \
      "https://haveibeenpwned.com/api/v3/breachedaccount/target@example.com" \
      -o /tmp/osint/breach-results.json
Phase 2 — Data Normalization
  1. Normalize all collected data into a common schema. Create a unified JSON structure that tags each finding with its source, timestamp, and data type:

    bash
    cat > /tmp/osint/normalize.py << 'EOF'
    import json, csv, sys, os
    from datetime import datetime
    
    findings = []
    
    # Normalize Sherlock CSV results
    sherlock_path = "/tmp/osint/sherlock-results.txt"
    if os.path.exists(sherlock_path):
        with open(sherlock_path) as f:
            for row in csv.DictReader(f):
                findings.append({
                    "source": "sherlock",
                    "type": "social_profile",
                    "platform": row.get("name", ""),
                    "url": row.get("url_user", ""),
                    "username": row.get("username", ""),
                    "status": row.get("status", ""),
                    "collected_at": datetime.utcnow().isoformat()
                })
    
    # Normalize theHarvester JSON results
    harvester_path = "/tmp/osint/harvester-results.json"
    if os.path.exists(harvester_path):
        with open(harvester_path) as f:
            data = json.load(f)
            for email in data.get("emails", []):
                findings.append({
                    "source": "theHarvester",
                    "type": "email",
                    "value": email,
                    "collected_at": datetime.utcnow().isoformat()
                })
            for host in data.get("hosts", []):
                findings.append({
                    "source": "theHarvester",
                    "type": "hostname",
                    "value": host,
                    "collected_at": datetime.utcnow().isoformat()
                })
    
    # Normalize SpiderFoot results
    sf_path = "/tmp/osint/spiderfoot-results.json"
    if os.path.exists(sf_path):
        with open(sf_path) as f:
            for item in json.load(f):
                findings.append({
                    "source": "spiderfoot",
                    "type": item.get("type", "unknown"),
                    "value": item.get("data", ""),
                    "module": item.get("module", ""),
                    "collected_at": datetime.utcnow().isoformat()
                })
    
    with open("/tmp/osint/normalized-findings.json", "w") as f:
        json.dump(findings, f, indent=2)
    
    print(f"Normalized {len(findings)} findings from {len(set(f['source'] for f in findings))} sources")
    EOF
    python3 /tmp/osint/normalize.py
Phase 3 — AI-Driven Correlation
  1. Send normalized findings to an LLM for cross-source correlation analysis:

    bash
    cat > /tmp/osint/correlate.py << 'PYEOF'
    import json, os
    from openai import OpenAI  # or anthropic, ollama, etc.
    
    client = OpenAI(api_key=os.environ["OPENAI_API_KEY"])
    
    with open("/tmp/osint/normalized-findings.json") as f:
        findings = json.load(f)
    
    correlation_prompt = f"""You are an OSINT analyst. Analyze these findings collected
    from multiple sources and produce a correlation report.
    
    For each identity or entity you detect:
    1. List all linked accounts/profiles with the evidence connecting them.
    2. Assign a confidence score (0.0-1.0) for each linkage based on:
       - Exact username match across platforms (high)
       - Similar usernames with shared metadata (medium)
       - Same email in breach data and registration (high)
       - Co-occurring infrastructure (IP, domain) (medium)
       - Temporal correlation of account creation dates (low-medium)
    3. Identify contradictions or potential false positives.
    4. Flag high-risk exposures (breached credentials, PII leaks, infrastructure overlaps).
    5. Produce a structured JSON report.
    
    Raw findings:
    {json.dumps(findings[:500], indent=2)}
    """
    
    response = client.chat.completions.create(
        model="gpt-4o",
        messages=[
            {"role": "system", "content": "You are an expert OSINT analyst specializing in identity correlation and link analysis."},
            {"role": "user", "content": correlation_prompt}
        ],
        temperature=0.1,
        response_format={"type": "json_object"}
    )
    
    report = json.loads(response.choices[0].message.content)
    
    with open("/tmp/osint/correlation-report.json", "w") as f:
        json.dump(report, f, indent=2)
    
    print(json.dumps(report, indent=2))
    PYEOF
    python3 /tmp/osint/correlate.py
  2. Perform entity resolution — deduplicate and merge related identities:

    bash
    cat > /tmp/osint/resolve.py << 'PYEOF'
    import json
    
    with open("/tmp/osint/correlation-report.json") as f:
        report = json.load(f)
    
    # Extract entities and build a link graph
    entities = report.get("entities", [])
    print(f"Identified {len(entities)} distinct entities")
    for entity in entities:
        name = entity.get("identifier", "unknown")
        confidence = entity.get("confidence", 0)
        links = entity.get("linked_accounts", [])
        risk = entity.get("risk_level", "unknown")
        print(f"  [{confidence:.0%}] {name} — {len(links)} linked accounts — risk: {risk}")
    PYEOF
    python3 /tmp/osint/resolve.py
Show full SKILL.md (479 more words)Show less
Phase 4 — Reporting and Visualization
  1. Generate a final intelligence profile in Markdown:

    bash
    cat > /tmp/osint/report.py << 'PYEOF'
    import json
    from datetime import datetime
    
    with open("/tmp/osint/correlation-report.json") as f:
        report = json.load(f)
    
    md = f"# OSINT Correlation Report\n\n"
    md += f"**Generated:** {datetime.utcnow().isoformat()}Z\n\n"
    md += "## Entity Profiles\n\n"
    
    for entity in report.get("entities", []):
        eid = entity.get("identifier", "Unknown")
        conf = entity.get("confidence", 0)
        md += f"### {eid} (Confidence: {conf:.0%})\n\n"
        md += "| Source | Platform | Evidence |\n|--------|----------|----------|\n"
        for link in entity.get("linked_accounts", []):
            md += f"| {link.get('source','')} | {link.get('platform','')} | {link.get('evidence','')} |\n"
        md += f"\n**Risk Level:** {entity.get('risk_level', 'N/A')}\n\n"
        for flag in entity.get("flags", []):
            md += f"- ⚠️ {flag}\n"
        md += "\n"
    
    with open("/tmp/osint/intelligence-profile.md", "w") as f:
        f.write(md)
    
    print("Report written to /tmp/osint/intelligence-profile.md")
    PYEOF
    python3 /tmp/osint/report.py
  2. Optional — Import correlation graph into Maltego for visualization:

    bash
    # Export entities as Maltego-compatible CSV for manual import
    cat > /tmp/osint/maltego_export.py << 'PYEOF'
    import json, csv
    
    with open("/tmp/osint/correlation-report.json") as f:
        report = json.load(f)
    
    with open("/tmp/osint/maltego-import.csv", "w", newline="") as f:
        writer = csv.writer(f)
        writer.writerow(["Entity Type", "Value", "Linked To", "Link Label", "Confidence"])
        for entity in report.get("entities", []):
            for link in entity.get("linked_accounts", []):
                writer.writerow([
                    link.get("type", "Alias"),
                    link.get("value", ""),
                    entity.get("identifier", ""),
                    link.get("evidence", ""),
                    link.get("confidence", "")
                ])
    
    print("Maltego CSV exported to /tmp/osint/maltego-import.csv")
    PYEOF
    python3 /tmp/osint/maltego_export.py

Key Concepts

ConceptDescription
Cross-Source CorrelationMatching identifiers (usernames, emails, IPs) across independent OSINT sources to establish entity linkage
Confidence ScoringAssigning probabilistic confidence (0.0–1.0) to each linkage based on evidence strength and corroboration
Entity ResolutionDeduplicating and merging records that refer to the same real-world entity across fragmented datasets
False Positive DetectionUsing AI reasoning to identify coincidental matches versus genuine identity links
Multi-Vector IntelligenceCombining findings from social media, DNS, breach data, and infrastructure into a single threat picture
Link AnalysisGraph-based examination of relationships between entities, accounts, and infrastructure

Tools & Systems

ToolRole in Workflow
SherlockUsername enumeration across 400+ social platforms
theHarvesterEmail, subdomain, and host discovery from public sources
SpiderFootAutomated OSINT collection across 200+ modules
MaltegoGraph-based visualization of entity relationships
LLM API (GPT-4, Claude, Ollama)Cross-source reasoning, pattern detection, and confidence scoring
HaveIBeenPwnedBreach exposure and credential leak detection

Common Scenarios

  • Threat Actor Attribution: Correlate a suspicious username found in a phishing campaign with social media profiles, domain registrations, and breach data to build an attribution profile.
  • Attack Surface Mapping: Link discovered subdomains, emails, and employee social accounts to understand an organization's full external exposure.
  • Insider Threat Investigation: Cross-reference an employee's known accounts with dark web marketplace activity and breach databases.
  • Brand Impersonation Detection: Identify accounts across platforms mimicking a target brand by correlating registration patterns, naming conventions, and temporal signals.

Output Format

The final output is a structured JSON correlation report and a Markdown intelligence profile containing:

json
{
  "meta": {
    "target": "targetdomain.com",
    "sources_used": ["sherlock", "theHarvester", "spiderfoot", "hibp"],
    "total_findings": 247,
    "generated_at": "2025-01-15T14:30:00Z"
  },
  "entities": [
    {
      "identifier": "john.target",
      "confidence": 0.92,
      "linked_accounts": [
        {
          "source": "sherlock",
          "platform": "GitHub",
          "value": "john.target",
          "evidence": "Exact username match, bio references targetdomain.com",
          "confidence": 0.95
        }
      ],
      "risk_level": "high",
      "flags": [
        "Credentials exposed in 2 breaches (2022, 2023)",
        "Admin email for targetdomain.com found in public WHOIS"
      ]
    }
  ],
  "contradictions": [],
  "recommendations": []
}

Verification

  • Confirm that each linked account has been independently verified against at least two sources before assigning confidence > 0.8.
  • Cross-check AI-generated correlations manually for a random sample (10–20%) to validate accuracy.
  • Verify that no false positives from common usernames (e.g., "admin", "test") inflated entity profiles.
  • Ensure breach data timestamps are current and from reputable aggregators.
  • Validate that the final report does not include stale or retracted OSINT data.

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/performing-ai-driven-osint-correlation of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Performing AI Driven Osint Correlation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Performing AI Driven Osint Correlation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Performing AI Driven Osint Correlation this skillmukul975/Anthropic-Cybersecurity-Skills34k—~3.6kAutomated safety check: PassApache-2.0
Metabigor OSINT Reconj3ssie/metabigor1.8k—~2.4kAutomated safety check: PassMIT
Ctf Osintljagiello/ctf-skills3.4k1 repos~2.3kAutomated safety check: NotesMIT
ShadowBroker Intelligence ClientBigBodyCobain/Shadowbroker11k—~8.9kAutomated safety check: WarnAGPL-3.0
Awesome Osint Operatorshoyann/RZK-The-Hunter141—~4.8kAutomated safety check: PassCC-BY-SA-4.0
Run Claude Osintelementalsouls/Claude-OSINT2.8k—~1.2kAutomated safety check: PassMIT

Similar skills

  • Metabigor OSINT Recon

    j3ssie/metabigor

    Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys.

    1.8k GitHub stars~2.4k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Ctf Osint

    ljagiello/ctf-skills

    Provides open source intelligence techniques for CTF challenges.

    3.4k GitHub starsUsed in 1 repo~2.3k tokens
    SecurityAuto-check: notes
  • ShadowBroker Intelligence Client

    BigBodyCobain/Shadowbroker

    Lets an agent query a ShadowBroker OSINT platform for tracked flights, ships, satellites and news, and place its findings on the map as intel pins.

    11k GitHub stars~8.9k tokensUpdated yesterday
    SecurityAuto-check: warnings
  • Awesome Osint Operator

    shoyann/RZK-The-Hunter

    Ethical, evidence-first OSINT planning, tool selection, verification, monitoring, reporting, and guarded official wanted/fugitive-person location intelligence using a structured catalog adapted from…

    141 GitHub stars~4.8k tokensUpdated yesterday
    SecurityAuto-check passed
  • Run Claude Osint

    elementalsouls/Claude-OSINT

    Build, validate, and run the claude-osint skills repo — check SKILL.md frontmatter, run the secretscan.py and h1reference.py helpers, run sync-skill-content.sh, run the smoke test.

    2.8k GitHub stars~1.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Osint

    smixs/osint-skill

    Conduct deep OSINT research on individuals. An agent skill from smixs/osint-skill.

    141 GitHub stars~5.5k tokensUpdated 7 mo ago
    SecurityAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Performing AI Driven Osint Correlation

What does Performing AI Driven Osint Correlation do?

Use AI/LLM-based reasoning with Sherlock, theHarvester, and SpiderFoot to correlate OSINT findings—usernames, emails, social profiles, domain records, breach databases, and dark-web mentions—into…. Performing AI Driven Osint Correlation is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Use AI/LLM-based reasoning with Sherlock, theHarvester, and SpiderFoot to correlate OSINT findings—usernames, emails, social profiles, domain records, breach databases, and dark-web mentions—into unified, confidence-scored intelligence profiles with link analysis.

When should I use Performing AI Driven Osint Correlation?

Performing AI Driven Osint Correlation fits situations like: raw OSINT data from multiple sources needs merging into one target profile; resolving identity linkage across platforms.

How do I install Performing AI Driven Osint Correlation in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-ai-driven-osint-correlation -a claude-code`. Or copy the skill folder (skills/performing-ai-driven-osint-correlation in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/performing-ai-driven-osint-correlation in your project. Claude Code loads it when a task matches its description.

How do I install Performing AI Driven Osint Correlation in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-ai-driven-osint-correlation -a codex`. Or copy the skill folder (skills/performing-ai-driven-osint-correlation in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/performing-ai-driven-osint-correlation in your project. Codex loads it when a task matches its description.

Can I use Performing AI Driven Osint Correlation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-ai-driven-osint-correlation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/performing-ai-driven-osint-correlation, .gemini/skills/performing-ai-driven-osint-correlation, .github/skills/performing-ai-driven-osint-correlation and .opencode/skills/performing-ai-driven-osint-correlation in your project.

What does Performing AI Driven Osint Correlation need to run?

Going by SKILL.md and its folder, Performing AI Driven Osint Correlation needs Python for the scripts in its folder, the command-line tools its instructions call (python3, curl, pip and jq) and credentials named HIBP_KEY and OPENAI_API_KEY. Our summary lists: Python 3; A credential in HIBP_KEY; A credential in OPENAI_API_KEY.

Does Performing AI Driven Osint Correlation access the network?

SKILL.md names 2 domains. In commands or code: haveibeenpwned.com; the agent is likely to contact it when it follows the instructions. As links in the text: github.com. This is read from the text; nothing was executed.

Is Performing AI Driven Osint Correlation safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Performing AI Driven Osint Correlation use?

Performing AI Driven Osint Correlation is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Performing AI Driven Osint Correlation use?

About 3.6k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.3k tokens, read only when the agent opens those files.

What are the alternatives to Performing AI Driven Osint Correlation?

Skills that share tags, products or a category with Performing AI Driven Osint Correlation: Metabigor OSINT Recon (j3ssie/metabigor, 1.8k stars), Ctf Osint (ljagiello/ctf-skills, 3.4k stars), ShadowBroker Intelligence Client (BigBodyCobain/Shadowbroker, 11k stars) and Awesome Osint Operator (shoyann/RZK-The-Hunter, 141 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Performing AI Driven Osint Correlation?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 33,993 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.