Metabigor OSINT Recon
j3ssie/metabigor
Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys.
Interact with Microsoft Teams — send and read messages, search conversations, look up people, check calendar, get meeting transcripts, and manage chats.
$ npx skills add sigcli/sigcli --skill msteams -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install sigcli/sigcli msteams --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/sigcli/sigcli.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/msteams .claude/skills/msteams && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "msteams" agent skill from https://github.com/sigcli/sigcli/tree/main/skills/msteams into .claude/skills/msteams/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "msteams", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/sigcli/sigcli/tree/main/skills/msteamsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add sigcli/sigcli --skill msteams -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install sigcli/sigcli msteams --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sigcli/sigcli.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/msteams .agents/skills/msteams && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "msteams" agent skill from https://github.com/sigcli/sigcli/tree/main/skills/msteams into .agents/skills/msteams/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "msteams", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add sigcli/sigcli --skill msteams -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install sigcli/sigcli msteams --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sigcli/sigcli.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/msteams .cursor/skills/msteams && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "msteams" agent skill from https://github.com/sigcli/sigcli/tree/main/skills/msteams into .cursor/skills/msteams/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "msteams", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/sigcli/sigcli.git --path skills/msteams--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add sigcli/sigcli --skill msteams -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install sigcli/sigcli msteams --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sigcli/sigcli.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/msteams .gemini/skills/msteams && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "msteams" agent skill from https://github.com/sigcli/sigcli/tree/main/skills/msteams into .gemini/skills/msteams/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "msteams", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install sigcli/sigcli msteamsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add sigcli/sigcli --skill msteams -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/sigcli/sigcli.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/msteams .github/skills/msteams && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "msteams" agent skill from https://github.com/sigcli/sigcli/tree/main/skills/msteams into .github/skills/msteams/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "msteams", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add sigcli/sigcli --skill msteams -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install sigcli/sigcli msteams --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sigcli/sigcli.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/msteams .opencode/skills/msteams && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "msteams" agent skill from https://github.com/sigcli/sigcli/tree/main/skills/msteams into .opencode/skills/msteams/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "msteams", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
msteamsInteract with Microsoft Teams — send and read messages, search conversations, look up people, check calendar, get meeting transcripts, and manage chats.
Msteams is an agent skill from sigcli/sigcli. Interact with Microsoft Teams — send and read messages, search conversations, look up people, check calendar, get meeting transcripts, and manage chats. Use this skill whenever the user mentions Teams, MS Teams, Microsoft Teams, wants to send a message, read chat history, search conversations, look up a colleague, check their calendar, find meeting recordings or transcripts, see direct reports or manager, or do anything involving Teams communication. Also trigger when the user asks about scheduling, org chart…
Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 22 other files, including scripts and reference files (for example `references/messaging-guide.md`, `references/provider-config.yaml` and `scripts/teams_calendar.py`).
It sits in Security, covering OSINT. It works with Microsoft Teams. The repository describes itself as: The authentication CLI & Proxy for AI agents. Give agents access, not your credentials. The licence is MIT.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 9ba8b35. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 9 files in scripts/ (Python, from the files we listed), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
SIG_MS_TEAMS_ACCESS_TOKENSIG_MS_GRAPH_ACCESS_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Msteams loads about 2.7k tokens when it runs, and up to ~4.2k if it reads all its reference files. Until then it costs about 142 tokens; SKILL.md has 777 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from sigcli/sigcli at commit 9ba8b35, republished under its MIT licence (© sigcli). 777 words, ~2,735 tokens.
.claude/skills/msteams/SKILL.md (or your agent's skills folder). This skill also uses 19 other files; get the full folder from GitHub.Send and read messages, search conversations, look up people, check calendar, get meeting transcripts, and manage chats via Microsoft Teams.
You MUST complete this setup before running any script. Do NOT skip this step.
sig status ms-teams 2>&1
sig status ms-graph 2>&1Check the JSON output fields configured and valid for BOTH providers:
configured: false → run Provider Setup below. Do NOT proceed without completing it.valid: false (but configured: true) → run sig login ms-teams, then re-check.valid: true → detect proxy (see below), then execute the user's request.<SKILL_DIR>/references/provider-config.yamlms-teams and ms-graph) to ~/.sig/config.yaml under providers:networkProxy: <url> under each provider in config.yamlsig login ms-teams (with --network-proxy <url> if proxy was specified) — this covers both providerssig status ms-teams and sig status ms-graph again — both must show valid: true before proceedinggrep -A15 "^\s*ms-teams:" ~/.sig/config.yaml | grep networkProxy | awk '{print $2}'If this outputs a URL, prefix ALL python3 commands with HTTPS_PROXY=<url> HTTP_PROXY=<url>.
If using socks5, convert to socks5h for python (e.g. socks5://... → socks5h://...).
If empty, no proxy needed.
All scripts require setup to be completed first (see above).
Before using this skill, check memory/user-profile.md for the user's stored profile (name, email, region, etc.). See CLAUDE.md for details.
All scripts support a --region parameter for the Teams Chat API regional endpoint. Resolution order:
memory/user-profile.md--region CLI argument (if provided)TEAMS_REGION environment variableapacCommon regions: apac, emea, amer.
Region: If the region is not in memory/user-profile.md or the env var, ask the user once, then store it immediately in memory/user-profile.md.
Profile enrichment: When you call teams_people.py --action profile (or Graph /me), persist the user's name, email, and I-number to memory/user-profile.md so other skills can use them without re-querying.
All scripts are in this skill's scripts/ directory. Run via Bash tool.
| Script | Purpose | Token(s) |
|---|---|---|
teams_conversations.py | List/search conversations | Chat |
teams_messages.py | Get messages from a conversation | Chat |
teams_send.py | Send message or threaded reply | Chat |
teams_chat.py | Find 1:1 chat or create group chat | Chat + Graph |
teams_members.py | Get conversation members | Chat + Graph |
teams_meetings.py | Get recordings and transcripts | Chat |
teams_calendar.py | Get calendar events | Graph |
teams_people.py | Search people, manager, reports, profile | Graph |
--token TOKEN Chat API token (required)
--search TEXT Filter by topic, participant, or content
--limit N Max conversations (default: 20)
--since ISO_DATE Only conversations after this time
--until ISO_DATE Only conversations before this time
--region REGION Teams region (default: $TEAMS_REGION or 'apac')--token TOKEN Chat API token (required)
--conversation-id ID Conversation ID (required)
--search TEXT Filter messages by content
--limit N Max messages (default: 20, use 50+ for summarization)
--since ISO_DATE Only messages after this time
--until ISO_DATE Only messages before this time
--region REGION Teams region (default: $TEAMS_REGION or 'apac')--token TOKEN Chat API token (required)
--conversation-id ID Conversation ID (required)
--message TEXT Message content (required)
--format FORMAT "html" (default) or "markdown"
--parent-message-id ID Parent message ID (for threaded replies)
--region REGION Teams region (default: $TEAMS_REGION or 'apac')--token TOKEN Chat API token (required)
--graph-token TOKEN Graph API token (required)
--query TEXT Person name/email (finds 1:1 chat)
--members GUIDS Comma-separated user GUIDs (creates group chat)
--topic TEXT Group chat topic (optional)
--region REGION Teams region (default: $TEAMS_REGION or 'apac')--token TOKEN Chat API token (required)
--graph-token TOKEN Graph API token (for name resolution, optional)
--conversation-id ID Conversation ID (required)
--region REGION Teams region (default: $TEAMS_REGION or 'apac')--token TOKEN Chat API token (required)
--conversation-id ID List recordings in conversation
--transcript-url URL Fetch transcript content (Teams AMS URL only)
--region REGION Teams region (default: $TEAMS_REGION or 'apac')--graph-token TOKEN Graph API token (required)
--range RANGE "today", "week", or "month"
--start ISO_DATE Custom start date (alternative to --range)
--end ISO_DATE Custom end date (use with --start)
--limit N Max events (default: 50)--graph-token TOKEN Graph API token (required)
--action ACTION "search" (default), "manager", "reports", or "profile"
--query TEXT Search query (required for search action)
--limit N Max results (default: 10)
--enrich Fetch extra details (I-number, city, country)When sending messages, use --format html (default) for rich formatting:
<b>Bold</b>, <i>Italic</i>, <a href="url">Link</a>
<ul>
<li>Item</li>
</ul>
,
<ol>
<li>Item</li>
</ol>
<pre>Code block</pre>
, <code>Inline code</code>Or --format markdown for Teams markdown:
**bold**, _italic_, ~~strikethrough~~
`code`, [link](url), - bullet, 1. numberedSee references/messaging-guide.md for complete formatting reference.
Conversation IDs — Unique identifiers for chats/channels. Format varies by type:
19:{guid1}_{guid2}@unq.gbl.spaces19:{hash}@thread.tacv2User GUIDs — Microsoft 365 user identifiers (e.g., abc12345-def6-7890-...). Get from teams_people.py --action search.
Transcript URLs — Only Teams AMS URLs (asyncgw.teams.microsoft.com) work with the Chat API token. SharePoint URLs require different auth.
Time parameters — All use ISO 8601: 2025-01-15 or 2025-01-15T09:00:00Z.
| Error | Cause | Fix |
|---|---|---|
| 401 Unauthorized | Token expired | Auto-run sig login (no user prompt needed), retry |
| 403 Forbidden | No access to conversation | User lacks permission |
| 404 Not found | Invalid conversation ID | Check ID format, conversation may not exist |
NOT_FOUND (people) | No user matching query | Try a more specific name or email |
MISSING_ARGS | Required arguments missing | Check script --help for required args |
| Multiple candidates | Ambiguous people search | Ask user to specify more precisely |
sig run ms-teams ms-graph -- bash -c 'python scripts/teams_chat.py --token "$SIG_MS_TEAMS_ACCESS_TOKEN" --graph-token "$SIG_MS_GRAPH_ACCESS_TOKEN" --query "John Smith" --region apac'sig run ms-teams -- bash -c 'python scripts/teams_send.py --token "$SIG_MS_TEAMS_ACCESS_TOKEN" --conversation-id "$CONV_ID" --message "Hello!" --region apac'sig run ms-teams -- bash -c 'python scripts/teams_conversations.py --token "$SIG_MS_TEAMS_ACCESS_TOKEN" --search "project standup"'sig run ms-teams -- bash -c 'python scripts/teams_messages.py --token "$SIG_MS_TEAMS_ACCESS_TOKEN" --conversation-id "$CONV_ID" --limit 50'sig run ms-teams -- bash -c 'python scripts/teams_meetings.py --token "$SIG_MS_TEAMS_ACCESS_TOKEN" --conversation-id "$CONV_ID"'sig run ms-teams -- bash -c 'python scripts/teams_meetings.py --token "$SIG_MS_TEAMS_ACCESS_TOKEN" --transcript-url "$AMS_URL"'sig run ms-graph -- bash -c 'python scripts/teams_calendar.py --graph-token "$SIG_MS_GRAPH_ACCESS_TOKEN" --range today'sig run ms-graph -- bash -c 'python scripts/teams_people.py --graph-token "$SIG_MS_GRAPH_ACCESS_TOKEN" --action search --query "Jane Doe" --enrich'sig run ms-graph -- bash -c 'python scripts/teams_people.py --graph-token "$SIG_MS_GRAPH_ACCESS_TOKEN" --action manager'sig run ms-graph -- bash -c 'python scripts/teams_people.py --graph-token "$SIG_MS_GRAPH_ACCESS_TOKEN" --action reports'sig run ms-teams -- bash -c 'python scripts/teams_messages.py --token "$SIG_MS_TEAMS_ACCESS_TOKEN" --conversation-id "$CONV_ID" --limit 10'sig run ms-teams -- bash -c 'python scripts/teams_send.py --token "$SIG_MS_TEAMS_ACCESS_TOKEN" --conversation-id "$CONV_ID" --parent-message-id "$MSG_ID" --message "Thanks!"'© sigcli, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 19 other files (scripts, references) in skills/msteams of sigcli/sigcli.
Open the folder on GitHubat commit 9ba8b35
Msteams next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Msteams this skillsigcli/sigcli | 293 | — | ~2.7k | Automated safety check: Pass | MIT | |
| Metabigor OSINT Reconj3ssie/metabigor | 1.8k | — | ~2.4k | Automated safety check: Pass | MIT | |
| Ctf Osintljagiello/ctf-skills | 3.4k | 2 repos | ~2.3k | Automated safety check: Notes | MIT | |
| ShadowBroker Intelligence ClientBigBodyCobain/Shadowbroker | 11k | — | ~8.9k | Automated safety check: Warn | AGPL-3.0 | |
| Awesome Osint Operatorshoyann/RZK-The-Hunter | 140 | — | ~4.8k | Automated safety check: Pass | CC-BY-SA-4.0 | |
| Run Claude Osintelementalsouls/Claude-OSINT | 2.8k | — | ~1.2k | Automated safety check: Pass | MIT |
j3ssie/metabigor
Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys.
ljagiello/ctf-skills
Provides open source intelligence techniques for CTF challenges.
BigBodyCobain/Shadowbroker
Lets an agent query a ShadowBroker OSINT platform for tracked flights, ships, satellites and news, and place its findings on the map as intel pins.
shoyann/RZK-The-Hunter
Ethical, evidence-first OSINT planning, tool selection, verification, monitoring, reporting, and guarded official wanted/fugitive-person location intelligence using a structured catalog adapted from…
elementalsouls/Claude-OSINT
Build, validate, and run the claude-osint skills repo — check SKILL.md frontmatter, run the secretscan.py and h1reference.py helpers, run sync-skill-content.sh, run the smoke test.
smixs/osint-skill
Conduct deep OSINT research on individuals. An agent skill from smixs/osint-skill.
sigcli/sigcli
Interact with Bilibili (B站) — browse trending videos, view video details, read comments, search videos and users, view user profiles, like, coin, and favorite videos.
sigcli/sigcli
Interact with Hacker News (news.ycombinator.com) — browse top, new, and best stories, read item details and comment threads, look up user profiles, and search posts via Algolia.
sigcli/sigcli
Interact with LinkedIn — view your profile, browse other profiles, read the feed, search jobs/posts/people, get job details, create posts, like/unlike posts, comment, send connection requests, and…
sigcli/sigcli
Interact with Outlook email — read inbox, send emails, search messages, reply/forward, manage folders, download attachments.
sigcli/sigcli
Interact with Reddit — browse subreddits, read posts and comments, search content, view user profiles, post comments, vote, save posts, subscribe to subreddits.
sigcli/sigcli
Interact with Slack — read channels, search messages, check unreads, send messages, manage reactions, and look up users.
Works with
Categories
Interact with Microsoft Teams — send and read messages, search conversations, look up people, check calendar, get meeting transcripts, and manage chats. Msteams is an agent skill from sigcli/sigcli. Interact with Microsoft Teams — send and read messages, search conversations, look up people, check calendar, get meeting transcripts, and manage chats.
Msteams fits situations like: the user mentions Teams; microsoft Teams; wants to send a message; read chat history.
Run `npx skills add sigcli/sigcli --skill msteams -a claude-code`. Or copy the skill folder (skills/msteams in sigcli/sigcli) into .claude/skills/msteams in your project. Claude Code loads it when a task matches its description.
Run `npx skills add sigcli/sigcli --skill msteams -a codex`. Or copy the skill folder (skills/msteams in sigcli/sigcli) into .agents/skills/msteams in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sigcli/sigcli --skill msteams -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/msteams, .gemini/skills/msteams, .github/skills/msteams and .opencode/skills/msteams in your project.
Going by SKILL.md and its folder, Msteams needs Python for the scripts in its folder and credentials named SIG_MS_TEAMS_ACCESS_TOKEN and SIG_MS_GRAPH_ACCESS_TOKEN. Our summary lists: Python 3; A credential in SIG_MS_TEAMS_ACCESS_TOKEN; A credential in SIG_MS_GRAPH_ACCESS_TOKEN.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Msteams is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.4k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Msteams: Metabigor OSINT Recon (j3ssie/metabigor, 1.8k stars), Ctf Osint (ljagiello/ctf-skills, 3.4k stars), ShadowBroker Intelligence Client (BigBodyCobain/Shadowbroker, 11k stars) and Awesome Osint Operator (shoyann/RZK-The-Hunter, 140 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
sigcli (a GitHub organization) maintains it in sigcli/sigcli, which has 293 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on September 28, 2026.
Source: sigcli/sigcli on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.