Agent skill

Sherlock

by Tommy-yw in Tommy-yw/RunbookHermes

OSINT username search across 400+ social networks. An agent skill from Tommy-yw/RunbookHermes.

MITAuto-check passedSecurity

Install Sherlock

skills CLI
$ npx skills add Tommy-yw/RunbookHermes --skill sherlock -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Tommy-yw/RunbookHermes sherlock --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Tommy-yw/RunbookHermes.git skills-src && mkdir -p .claude/skills && cp -r skills-src/optional-skills/security/sherlock .claude/skills/sherlock && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sherlock
GitHub stars
546
Used in
3 other repos
Token cost
~1.5k tokens
SKILL.md length
678 words
Files
1
Skills in repo
38
Repo updated
First seen
Licence
MIT

At a glance

OSINT username search across 400+ social networks. An agent skill from Tommy-yw/RunbookHermes.

  • Works in 5 steps: Check if Sherlock is Installed → Extract Username → Build Command → …
  • Tasks that involve OSINT
  • SKILL.md covers When to Use, Requirements, Procedure and Pitfalls, plus 4 more sections
  • Calls pipx, pip and docker; reaches github.com and twitter.com

What it does

Sherlock is an agent skill from Tommy-yw/RunbookHermes. OSINT username search across 400+ social networks. Hunt down social media accounts by username.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering OSINT. It works with Docker. The repository describes itself as: Hermes-native AIOps agent for evidence-driven incident response, approval-gated remediation, and runbook learning. The licence is MIT.

When your agent uses it

  • Tasks that involve OSINT

Example prompts

  • “/sherlock”

Requirements

  • Python 3
  • Docker

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Check if Sherlock is Installed
  2. Extract Username
  3. Build Command
  4. Execute Search
  5. Parse and Present Results

What it can do on your machine

Read from SKILL.md and the folder at commit 7fd2b9a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pipx
    • pip
    • docker

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com
    • twitter.com
    • instagram.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sherlock loads about 1.5k tokens when it runs. Until then it costs about 26 tokens; SKILL.md has 678 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~26
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Tommy-yw/RunbookHermes at commit 7fd2b9a, republished under its MIT licence (© Tommy-yw). 678 words, ~1,500 tokens.

Download SKILL.mdSave it as .claude/skills/sherlock/SKILL.md (or your agent's skills folder).
name
sherlock
description
OSINT username search across 400+ social networks. Hunt down social media accounts by username.
version
1.0.0
author
unmodeled-tyler
license
MIT
prerequisites.commands
sherlock

Hunt down social media accounts by username across 400+ social networks using the Sherlock Project.

When to Use

  • User asks to find accounts associated with a username
  • User wants to check username availability across platforms
  • User is conducting OSINT or reconnaissance research
  • User asks "where is this username registered?" or similar

Requirements

  • Sherlock CLI installed: pipx install sherlock-project or pip install sherlock-project
  • Alternatively: Docker available (docker run -it --rm sherlock/sherlock)
  • Network access to query social platforms

Procedure

1. Check if Sherlock is Installed

Before doing anything else, verify sherlock is available:

bash
sherlock --version

If the command fails:

  • Offer to install: pipx install sherlock-project (recommended) or pip install sherlock-project
  • Do NOT try multiple installation methods — pick one and proceed
  • If installation fails, inform the user and stop
2. Extract Username

Extract the username directly from the user's message if clearly stated.

Examples where you should NOT use clarify:

  • "Find accounts for nasa" → username is nasa
  • "Search for johndoe123" → username is johndoe123
  • "Check if alice exists on social media" → username is alice
  • "Look up user bob on social networks" → username is bob

Only use clarify if:

  • Multiple potential usernames mentioned ("search for alice or bob")
  • Ambiguous phrasing ("search for my username" without specifying)
  • No username mentioned at all ("do an OSINT search")

When extracting, take the exact username as stated — preserve case, numbers, underscores, etc.

3. Build Command

Default command (use this unless user specifically requests otherwise):

bash
sherlock --print-found --no-color "<username>" --timeout 90

Optional flags (only add if user explicitly requests):

  • --nsfw — Include NSFW sites (only if user asks)
  • --tor — Route through Tor (only if user asks for anonymity)

Do NOT ask about options via clarify — just run the default search. Users can request specific options if needed.

Run via the terminal tool. The command typically takes 30-120 seconds depending on network conditions and site count.

Example terminal call:

json
{
  "command": "sherlock --print-found --no-color \"target_username\"",
  "timeout": 180
}
5. Parse and Present Results

Sherlock outputs found accounts in a simple format. Parse the output and present:

  1. Summary line: "Found X accounts for username 'Y'"
  2. Categorized links: Group by platform type if helpful (social, professional, forums, etc.)
  3. Output file location: Sherlock saves results to <username>.txt by default

Example output parsing:

[+] Instagram: https://instagram.com/username
[+] Twitter: https://twitter.com/username
[+] GitHub: https://github.com/username

Present findings as clickable links when possible.

Pitfalls

No Results Found

If Sherlock finds no accounts, this is often correct — the username may not be registered on checked platforms. Suggest:

  • Checking spelling/variation
  • Trying similar usernames with ? wildcard: sherlock "user?name"
  • The user may have privacy settings or deleted accounts
Show full SKILL.md (270 more words)Show less
Timeout Issues

Some sites are slow or block automated requests. Use --timeout 120 to increase wait time, or --site to limit scope.

Tor Configuration

--tor requires Tor daemon running. If user wants anonymity but Tor isn't available, suggest:

  • Installing Tor service
  • Using --proxy with an alternative proxy
False Positives

Some sites always return "found" due to their response structure. Cross-reference unexpected results with manual checks.

Rate Limiting

Aggressive searches may trigger rate limits. For bulk username searches, add delays between calls or use --local with cached data.

Installation

bash
pipx install sherlock-project
pip
bash
pip install sherlock-project
Docker
bash
docker pull sherlock/sherlock
docker run -it --rm sherlock/sherlock <username>
Linux packages

Available on Debian 13+, Ubuntu 22.10+, Homebrew, Kali, BlackArch.

Ethical Use

This tool is for legitimate OSINT and research purposes only. Remind users:

  • Only search usernames they own or have permission to investigate
  • Respect platform terms of service
  • Do not use for harassment, stalking, or illegal activities
  • Consider privacy implications before sharing results

Verification

After running sherlock, verify:

  1. Output lists found sites with URLs
  2. <username>.txt file created (default output) if using file output
  3. If --print-found used, output should only contain [+] lines for matches

Example Interaction

User: "Can you check if the username 'johndoe123' exists on social media?"

Agent procedure:

  1. Check sherlock --version (verify installed)
  2. Username provided — proceed directly
  3. Run: sherlock --print-found --no-color "johndoe123" --timeout 90
  4. Parse output and present links

Response format:

Found 12 accounts for username 'johndoe123':

• https://twitter.com/johndoe123 • https://github.com/johndoe123 • https://instagram.com/johndoe123 • [... additional links]

Results saved to: johndoe123.txt


User: "Search for username 'alice' including NSFW sites"

Agent procedure:

  1. Check sherlock installed
  2. Username + NSFW flag both provided
  3. Run: sherlock --print-found --no-color --nsfw "alice" --timeout 90
  4. Present results

© Tommy-yw, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in optional-skills/security/sherlock of Tommy-yw/RunbookHermes.

Open the folder on GitHubat commit 7fd2b9a

Used in 3 other repositories

We found 3 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 3 other GitHub owners. This page covers the copy in Tommy-yw/RunbookHermes, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Sherlock next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sherlock compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sherlock this skillTommy-yw/RunbookHermes5463 repos~1.5kAutomated safety check: PassMIT
Building Threat Intelligence Platformmukul975/Anthropic-Cybersecurity-Skills34k—~2.5kAutomated safety check: PassApache-2.0
Collecting Threat Intelligence With Mispmukul975/Anthropic-Cybersecurity-Skills34k—~1.6kAutomated safety check: NotesApache-2.0
Building Threat Feed Aggregation With Mispmukul975/Anthropic-Cybersecurity-Skills34k—~3.2kAutomated safety check: PassApache-2.0
Building Ioc Enrichment Pipeline With Openctimukul975/Anthropic-Cybersecurity-Skills34k—~2.5kAutomated safety check: PassApache-2.0
Code Audit3stoneBrother/code-audit8931 repos~2.7kAutomated safety check: PassNone

Similar skills

  • Building Threat Intelligence Platform

    mukul975/Anthropic-Cybersecurity-Skills

    Design and deploy a Threat Intelligence Platform (TIP) by integrating open-source CTI tools (MISP, OpenCTI, TheHive, Cortex) into a unified system with feed ingestion pipelines, enrichment…

    34k GitHub stars~2.5k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Collecting Threat Intelligence With Misp

    mukul975/Anthropic-Cybersecurity-Skills

    Deploy MISP, configure threat feeds (MISP community, freetext, TAXII, CSV), and use the PyMISP API to programmatically fetch, add, and search events and IOCs, building automated collection pipelines…

    34k GitHub stars~1.6k tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • Building Threat Feed Aggregation With Misp

    mukul975/Anthropic-Cybersecurity-Skills

    Deploy MISP via Docker and configure feeds from sources like abuse.ch, AlienVault OTX, and CIRCL to aggregate, correlate, and distribute threat intelligence, including automated feed synchronization…

    34k GitHub stars~3.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Building Ioc Enrichment Pipeline With Opencti

    mukul975/Anthropic-Cybersecurity-Skills

    Build an automated IOC enrichment pipeline on OpenCTI (STIX 2.1 native threat intel platform) using its internal enrichment connectors to pull context from VirusTotal, Shodan, AbuseIPDB, and…

    34k GitHub stars~2.5k tokensUpdated 1 mo ago
    Product & Project ManagementAuto-check passed
  • Code Audit

    3stoneBrother/code-audit

    Professional code security audit skill covering 55+ vulnerability types.

    893 GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check passed
  • Codeql

    elastic/kibana

    Official

    Work with CodeQL in Kibana — write, test, and debug custom queries locally, fetch scan results from GitHub, and validate inline suppression comments.

    21k GitHub stars~1.7k tokensUpdated today
    SecurityAuto-check passed

More from Tommy-yw/RunbookHermes

All 38 skills in this repo
  • Fastmcp

    Tommy-yw/RunbookHermes

    Build, test, inspect, install, and deploy MCP servers with FastMCP in Python.

    546 GitHub starsUsed in 4 repos~2.1k tokens
    Auto-check passed
  • Drug Discovery

    Tommy-yw/RunbookHermes

    Pharmaceutical research assistant for drug discovery workflows.

    546 GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed
  • Youtube Content

    Tommy-yw/RunbookHermes

    Fetch YouTube video transcripts and transform them into structured content (chapters, summaries, threads, blog posts).

    546 GitHub starsUsed in 1 repo~785 tokens
    Auto-check passed
  • Oss Forensics

    Tommy-yw/RunbookHermes

    Supply chain investigation, evidence recovery, and forensic analysis for GitHub repositories.

    546 GitHub starsUsed in 3 repos~5k tokens
    Auto-check passed
  • P5js

    Tommy-yw/RunbookHermes

    Production pipeline for interactive and generative visual art using p5.js.

    546 GitHub starsUsed in 1 repo~6.8k tokens
    Auto-check passed
  • 1password

    Tommy-yw/RunbookHermes

    Set up and use 1Password CLI (op). An agent skill from Tommy-yw/RunbookHermes.

    546 GitHub starsUsed in 2 repos~1.2k tokens
    Auto-check: notes

Works with

Categories

Questions about Sherlock

What does Sherlock do?

OSINT username search across 400+ social networks. An agent skill from Tommy-yw/RunbookHermes. Sherlock is an agent skill from Tommy-yw/RunbookHermes. OSINT username search across 400+ social networks.

When should I use Sherlock?

Sherlock fits situations like: tasks that involve OSINT.

How do I install Sherlock in Claude Code?

Run `npx skills add Tommy-yw/RunbookHermes --skill sherlock -a claude-code`. Or copy the skill folder (optional-skills/security/sherlock in Tommy-yw/RunbookHermes) into .claude/skills/sherlock in your project. Claude Code loads it when a task matches its description.

How do I install Sherlock in Codex?

Run `npx skills add Tommy-yw/RunbookHermes --skill sherlock -a codex`. Or copy the skill folder (optional-skills/security/sherlock in Tommy-yw/RunbookHermes) into .agents/skills/sherlock in your project. Codex loads it when a task matches its description.

Can I use Sherlock in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Tommy-yw/RunbookHermes --skill sherlock -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sherlock, .gemini/skills/sherlock, .github/skills/sherlock and .opencode/skills/sherlock in your project.

What does Sherlock need to run?

Going by SKILL.md and its folder, Sherlock needs the command-line tools its instructions call (pipx, pip and docker). Our summary lists: Python 3; Docker.

Does Sherlock access the network?

SKILL.md names 3 domains. In commands or code: github.com, twitter.com and instagram.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Sherlock safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Sherlock use?

Sherlock is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sherlock use?

About 1.5k tokens (SKILL.md is roughly 6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Sherlock?

Skills that share tags, products or a category with Sherlock: Building Threat Intelligence Platform (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Collecting Threat Intelligence With Misp (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Building Threat Feed Aggregation With Misp (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Building Ioc Enrichment Pipeline With Opencti (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sherlock?

Tommy-yw (a GitHub user) maintains it in Tommy-yw/RunbookHermes, which has 546 GitHub stars. The repository holds 38 skills in this directory. The repository was last updated on May 18, 2026.

Source: Tommy-yw/RunbookHermes on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.