Metabigor OSINT Recon
j3ssie/metabigor
Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys.
Ethical, evidence-first OSINT planning, tool selection, verification, monitoring, reporting, and guarded official wanted/fugitive-person location intelligence using a structured catalog adapted from…
$ npx skills add shoyann/RZK-The-Hunter --skill awesome-osint-operator -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install shoyann/RZK-The-Hunter awesome-osint-operator --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
Claude Code skills documentation · loads skills from .claude/skills/
Install the "awesome-osint-operator" agent skill from https://github.com/shoyann/RZK-The-Hunter/tree/main into .claude/skills/awesome-osint-operator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "awesome-osint-operator", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add shoyann/RZK-The-Hunter --skill awesome-osint-operator -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install shoyann/RZK-The-Hunter awesome-osint-operator --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "awesome-osint-operator" agent skill from https://github.com/shoyann/RZK-The-Hunter/tree/main into .agents/skills/awesome-osint-operator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "awesome-osint-operator", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add shoyann/RZK-The-Hunter --skill awesome-osint-operator -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install shoyann/RZK-The-Hunter awesome-osint-operator --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "awesome-osint-operator" agent skill from https://github.com/shoyann/RZK-The-Hunter/tree/main into .cursor/skills/awesome-osint-operator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "awesome-osint-operator", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add shoyann/RZK-The-Hunter --skill awesome-osint-operator -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install shoyann/RZK-The-Hunter awesome-osint-operator --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "awesome-osint-operator" agent skill from https://github.com/shoyann/RZK-The-Hunter/tree/main into .gemini/skills/awesome-osint-operator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "awesome-osint-operator", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install shoyann/RZK-The-Hunter awesome-osint-operatorInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add shoyann/RZK-The-Hunter --skill awesome-osint-operator -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "awesome-osint-operator" agent skill from https://github.com/shoyann/RZK-The-Hunter/tree/main into .github/skills/awesome-osint-operator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "awesome-osint-operator", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add shoyann/RZK-The-Hunter --skill awesome-osint-operator -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install shoyann/RZK-The-Hunter awesome-osint-operator --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "awesome-osint-operator" agent skill from https://github.com/shoyann/RZK-The-Hunter/tree/main into .opencode/skills/awesome-osint-operator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "awesome-osint-operator", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
awesome-osint-operatorEthical, evidence-first OSINT planning, tool selection, verification, monitoring, reporting, and guarded official wanted/fugitive-person location intelligence using a structured catalog adapted from…
Awesome Osint Operator is an agent skill from shoyann/RZK-The-Hunter. Ethical, evidence-first OSINT planning, tool selection, verification, monitoring, reporting, and guarded official wanted/fugitive-person location intelligence using a structured catalog adapted from jivoi/awesome-osint. Use for public-source domain, company, username, image, geospatial, news, fact-checking, defensive threat-intelligence, and verified official wanted-person research. Do not use for doxxing, stalking, credential acquisition, access bypass, continuous real-time tracking, or abusive/invasive profiling.
Its SKILL.md is about 4.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 71 other files, including scripts, reference files and assets (for example `.github/workflows/release.yml`, `ATTRIBUTION.md` and `CHANGELOG.md`).
It sits in Security, covering OSINT. The repository describes itself as: A parasitic investigation skill for AI agents. Adaptive research, verified sources, traceable evidence. The licence is CC-BY-SA-4.0.
8 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 0163321. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/, which the agent can run.
Shell commands in SKILL.md call:
pythonFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Awesome Osint Operator loads about 4.8k tokens when it runs, and up to ~416k if it reads all its reference files. Until then it costs about 136 tokens; SKILL.md has 2,143 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from shoyann/RZK-The-Hunter at commit 0163321, republished under its CC-BY-SA-4.0 licence (© shoyann). 2,143 words, ~4,759 tokens.
.claude/skills/awesome-osint-operator/SKILL.md (or your agent's skills folder). This skill also uses 66 other files; get the full folder from GitHub.Turn a giant tool list into a disciplined investigation workflow. The catalog is a lead generator, not evidence. A tool result is never a finding until it is independently verified and cited.
workflows/wanted-person-location-intelligence.md.Read references/safety-policy.md before any people, username, email, phone, breach, dark-web, threat-actor, or official wanted/fugitive task.
Read references/hypothesis-convergence.md before any multi-stage investigation, puzzle-like artifact chain, or task where a plausible early answer could be overturned by later evidence.
At a consequential branch decision or strategic stall, read references/adaptive-investigation-strategy.md. Use it to choose the next evidence-changing action; it adds no collection permissions and does not replace the convergence gate.
For an adult who is currently named in an active official wanted/fugitive notice, verify that status and identity first, then read workflows/wanted-person-location-intelligence.md before performing any person-location inference.
Capture:
Classify the request:
For guarded work, narrow scope, prefer first-party or official sources, and redact unnecessary PII. For wanted/fugitive cases, do not infer location until the dedicated activation gate has passed.
Choose the matching workflow:
workflows/domain-infrastructure.mdworkflows/company-org.mdworkflows/username-social.mdworkflows/people-public-interest.mdworkflows/wanted-person-location-intelligence.mdworkflows/email-phone-defensive.mdworkflows/image-video-geolocation.mdworkflows/news-fact-check.mdworkflows/threat-intelligence.mdworkflows/monitoring.mdRoute directly to workflows/wanted-person-location-intelligence.md only when all activation conditions are satisfied: active official wanted/fugitive status, strong identity match, adult target, lawful public-safety purpose, and public/lawfully supplied evidence. Otherwise remain in workflows/people-public-interest.md and do not infer current location.
Start from hypotheses and questions, not tools. Define what evidence would confirm or falsify each hypothesis.
Create two explicit queues before deep searching:
open, leading, contradicted, verified).For image/video tasks, first read references/visual-clue-taxonomy.md and create a clue inventory from templates/visual-clue-inventory.csv. Do not let the first readable sign, plaque, face, logo, QR payload, or reverse-image hit become the answer.
For structured visual carriers such as QR codes, barcodes, steganographic layouts, or deliberately transformed puzzle artifacts, preserve every reproducible decode separately and test source-signaled transformations such as rotation, mirror, inversion, threshold/channel changes, or alternate layers before treating one valid payload as exhaustive.
Compare a small set of feasible actions against the current evidence gap. Convert the leading hypothesis's fastest falsifier into an executable source/artifact check before deepening that branch; execute it or explain why a different action has greater expected value. Rank qualitatively by discrimination, source fit, cost, repetition and fidelity after applying scope/access/safety constraints.
Log the expected discriminator, actual result and resulting evidence change.
When rephrased queries return the same source lineages without narrowing the
question, consider an original artifact, representation/habitat pivot, documented
technique transfer, method search, or deterministic/manual fallback. Changing a
query or website alone is not progress. No fixed action count or tool order is
required. Use templates/strategy-checkpoint.md only when it helps a branch decision.
For historical questions, current representations are discovery leads until the required time is verified. Park unexplained clues with revisit triggers. Task wording, AI output and generatively reconstructed detail are not factual evidence.
The catalog helps implement the selected action; its rankings are not a case plan.
Search locally:
python scripts/search_catalog.py "reverse image metadata geolocation" --top 12
python scripts/search_catalog.py "域名 DNS 证书历史" --top 12
python scripts/select_tools.py --workflow domain --per-stage 2
python scripts/visual_case.py init case/image-001Defaults exclude restricted entries. Treat catalog cost/auth signals as hints only; verify them on the tool's current official page.
Selection criteria:
For visual investigations, collect frame-wide clues before web results: full-frame scene model, grid/semantic crops, uncertain transcriptions, clue-family scoring, and at least two competing candidates.
Use this source order unless the workflow says otherwise:
Work the primary-evidence queue before expanding a weak lead into broad web search. A search-engine match must not outrank an unresolved original artifact that could directly answer or falsify the question.
Pivot only on corroborated identifiers. Keep a pivot log so aliases, dates, domains, hashes, and locations do not become mixed across entities.
When a public-source collection route hits a CAPTCHA, classify it as an access barrier. Try lawful alternate public routes first. If the site presents ordinary human verification, pause for an operator checkpoint and resume only after the operator completes the challenge manually. Do not automate CAPTCHA solving or transfer verification/session material between environments.
For official wanted/fugitive-person cases, build a location timeline that separates source time, content time, inferred place, and freshness. Do not turn a historical or reposted clue into a current-location claim.
A high-confidence claim usually requires either:
Check:
For every leading hypothesis, explicitly ask:
Use references/evidence-confidence.md and references/hypothesis-convergence.md for the scoring and state-transition rules.
Do not produce a submission-safe final answer until all of the following are true:
For official wanted/fugitive-person location findings, also require the dedicated workflow's official-status recheck, freshness label, confidence, and strongest contradiction/falsification attempt before finalizing.
If the gate fails, continue investigating instead of guessing a precise answer.
If an answer is rejected or a new source contradicts it:
contradicted or lower its confidence.This is an investigation loop, not a wording-bruteforce loop.
Initialize a ledger:
python scripts/evidence_ledger.py init case/evidence.csv
python scripts/evidence_ledger.py add case/evidence.csv \
--claim "Example claim" \
--source-url "https://example.org/source" \
--source-title "Example source" \
--source-type primary \
--confidence medium \
--notes "What this source supports and what it does not"For local files, record hashes. Do not store unnecessary sensitive data.
Use this structure:
Clearly label:
For official wanted/fugitive-person cases, use the required output fields in workflows/wanted-person-location-intelligence.md, including notice source, status-check time, location finding, evidence timestamps, freshness, confidence, supporting sources, strongest contradiction, and handling note.
Use the user's language. Avoid dramatic wording; precision beats certainty theater.
Return 3–7 tools, grouped by investigation stage. For each: purpose, why it fits, risk/registration caveat, and fallback.
Return hypotheses, collection stages, source priorities, verification tests, stop conditions, and deliverables. Do not pretend collection has already happened.
Perform the plan, keep an evidence ledger and hypothesis ledger, cite all material claims, and publish a confidence-rated report only after the convergence gate passes.
Trace the claim to its earliest available source, validate media provenance, compare independent reporting, identify missing context, attempt falsification, and state a verdict with confidence.
Activate only for an adult with a current official wanted/fugitive notice and a strong identity match. Use public or lawfully supplied evidence to infer a bounded last-known or recently evidenced location, attach freshness and confidence, recheck official status before finalizing, and stop immediately if the notice is no longer active or only prohibited collection routes remain. Never convert this mode into continuous live surveillance or tactical apprehension guidance.
Define entities, keywords, negative keywords, feeds, cadence, alert threshold, deduplication, and escalation criteria. Do not monitor private individuals invasively. The official wanted/fugitive workflow does not authorize continuous minute-by-minute monitoring.
The included snapshot is from jivoi/awesome-osint. Refresh it when internet access is available:
python scripts/sync_catalog.py
python scripts/verify_package.pyThe source list is licensed CC BY-SA 4.0. Preserve ATTRIBUTION.md and LICENSE.txt when redistributing adaptations.
references/catalog.json, references/catalog.csvreferences/source/awesome-osint-README.mdreferences/tool-selection.mdreferences/query-playbook.mdreferences/safety-policy.mdreferences/evidence-confidence.mdreferences/hypothesis-convergence.mdreferences/adaptive-investigation-strategy.mdtemplates/strategy-checkpoint.mdreferences/trajectory-evaluation.mdreferences/visual-clue-taxonomy.mdworkflows/image-video-geolocation.mdworkflows/wanted-person-location-intelligence.mdtemplates/visual-clue-inventory.csvtemplates/location-candidate-matrix.csvtemplates/image-geolocation-report.mdtemplates/© shoyann, CC-BY-SA-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 66 other files (scripts, references, assets) in the repository root of shoyann/RZK-The-Hunter.
Open the folder on GitHubat commit 0163321
Awesome Osint Operator next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Awesome Osint Operator this skillshoyann/RZK-The-Hunter | 141 | — | ~4.8k | Automated safety check: Pass | CC-BY-SA-4.0 | |
| Metabigor OSINT Reconj3ssie/metabigor | 1.9k | — | ~2.4k | Automated safety check: Pass | MIT | |
| Ctf Osintljagiello/ctf-skills | 3.4k | 1 repos | ~2.3k | Automated safety check: Notes | MIT | |
| ShadowBroker Intelligence ClientBigBodyCobain/Shadowbroker | 11k | — | ~8.9k | Automated safety check: Warn | AGPL-3.0 | |
| Run Claude Osintelementalsouls/Claude-OSINT | 2.8k | — | ~1.2k | Automated safety check: Pass | MIT | |
| Osintsmixs/osint-skill | 141 | — | ~5.5k | Automated safety check: Pass | MIT |
j3ssie/metabigor
Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys.
ljagiello/ctf-skills
Provides open source intelligence techniques for CTF challenges.
BigBodyCobain/Shadowbroker
Lets an agent query a ShadowBroker OSINT platform for tracked flights, ships, satellites and news, and place its findings on the map as intel pins.
elementalsouls/Claude-OSINT
Build, validate, and run the claude-osint skills repo — check SKILL.md frontmatter, run the secretscan.py and h1reference.py helpers, run sync-skill-content.sh, run the smoke test.
smixs/osint-skill
Conduct deep OSINT research on individuals. An agent skill from smixs/osint-skill.
elementalsouls/Claude-OSINT
Comprehensive OSINT methodology for external red-team operations and authorized attack-surface assessments.
Categories
Ethical, evidence-first OSINT planning, tool selection, verification, monitoring, reporting, and guarded official wanted/fugitive-person location intelligence using a structured catalog adapted from…. Awesome Osint Operator is an agent skill from shoyann/RZK-The-Hunter. Ethical, evidence-first OSINT planning, tool selection, verification, monitoring, reporting, and guarded official wanted/fugitive-person location intelligence using a structured catalog adapted from jivoi/awesome-osint.
Awesome Osint Operator fits situations like: public-source domain; defensive threat-intelligence; verified official wanted-person research; credential acquisition.
Run `npx skills add shoyann/RZK-The-Hunter --skill awesome-osint-operator -a claude-code`. Or copy the skill folder (the shoyann/RZK-The-Hunter repository) into .claude/skills/awesome-osint-operator in your project. Claude Code loads it when a task matches its description.
Run `npx skills add shoyann/RZK-The-Hunter --skill awesome-osint-operator -a codex`. Or copy the skill folder (the shoyann/RZK-The-Hunter repository) into .agents/skills/awesome-osint-operator in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add shoyann/RZK-The-Hunter --skill awesome-osint-operator -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/awesome-osint-operator, .gemini/skills/awesome-osint-operator, .github/skills/awesome-osint-operator and .opencode/skills/awesome-osint-operator in your project.
Going by SKILL.md and its folder, Awesome Osint Operator needs the command-line tools its instructions call (python). Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Awesome Osint Operator is published under the CC-BY-SA-4.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.8k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 411k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Awesome Osint Operator: Metabigor OSINT Recon (j3ssie/metabigor, 1.9k stars), Ctf Osint (ljagiello/ctf-skills, 3.4k stars), ShadowBroker Intelligence Client (BigBodyCobain/Shadowbroker, 11k stars) and Run Claude Osint (elementalsouls/Claude-OSINT, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
shoyann (a GitHub user) maintains it in shoyann/RZK-The-Hunter, which has 141 GitHub stars. The repository was last updated on October 8, 2026.
Source: shoyann/RZK-The-Hunter on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.