Metabigor OSINT Recon
j3ssie/metabigor
Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys.
Shodan lookups: internet-connected devices, ports, services. An agent skill from taracodlabs/aiden.
$ npx skills add taracodlabs/aiden --skill shodan -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install taracodlabs/aiden shodan --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/taracodlabs/aiden.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/shodan .claude/skills/shodan && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "shodan" agent skill from https://github.com/taracodlabs/aiden/tree/main/skills/shodan into .claude/skills/shodan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "shodan", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/taracodlabs/aiden/tree/main/skills/shodanType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add taracodlabs/aiden --skill shodan -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install taracodlabs/aiden shodan --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/taracodlabs/aiden.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/shodan .agents/skills/shodan && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "shodan" agent skill from https://github.com/taracodlabs/aiden/tree/main/skills/shodan into .agents/skills/shodan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "shodan", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add taracodlabs/aiden --skill shodan -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install taracodlabs/aiden shodan --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/taracodlabs/aiden.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/shodan .cursor/skills/shodan && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "shodan" agent skill from https://github.com/taracodlabs/aiden/tree/main/skills/shodan into .cursor/skills/shodan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "shodan", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/taracodlabs/aiden.git --path skills/shodan--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add taracodlabs/aiden --skill shodan -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install taracodlabs/aiden shodan --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/taracodlabs/aiden.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/shodan .gemini/skills/shodan && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "shodan" agent skill from https://github.com/taracodlabs/aiden/tree/main/skills/shodan into .gemini/skills/shodan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "shodan", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install taracodlabs/aiden shodanInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add taracodlabs/aiden --skill shodan -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/taracodlabs/aiden.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/shodan .github/skills/shodan && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "shodan" agent skill from https://github.com/taracodlabs/aiden/tree/main/skills/shodan into .github/skills/shodan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "shodan", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add taracodlabs/aiden --skill shodan -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install taracodlabs/aiden shodan --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/taracodlabs/aiden.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/shodan .opencode/skills/shodan && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "shodan" agent skill from https://github.com/taracodlabs/aiden/tree/main/skills/shodan into .opencode/skills/shodan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "shodan", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
shodanShodan lookups: internet-connected devices, ports, services. An agent skill from taracodlabs/aiden.
Shodan is an agent skill from taracodlabs/aiden. Shodan lookups: internet-connected devices, ports, services
Its SKILL.md is about 950 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `index.ts` and `skill.json`).
It sits in Security, covering OSINT. The repository describes itself as: Aiden — an autonomous AI agent and work engine built solo. It can operate your browser, terminal, files, apps, APIs, skills and tools, remember context, recover from failures… The licence is Apache-2.0.
Read from SKILL.md and the folder at commit 3704204. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships script files (TypeScript), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
api.shodan.ioAlso links to:
account.shodan.ioFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
SHODAN_API_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Shodan loads about 954 tokens when it runs. Until then it costs about 17 tokens; SKILL.md has 263 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from taracodlabs/aiden at commit 3704204, republished under its Apache-2.0 licence (© taracodlabs). 263 words, ~954 tokens.
.claude/skills/shodan/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.Shodan indexes internet-connected devices and exposes metadata: open ports, running services, banners, TLS certificates, and known CVEs. Use it for security audits, reconnaissance, and asset discovery.
Requires: SHODAN_API_KEY — free tier at https://account.shodan.io (1 req/sec, 100 queries/month).
$ip = "8.8.8.8"
$key = $env:SHODAN_API_KEY
$url = "https://api.shodan.io/shodan/host/${ip}?key=${key}"
$host = Invoke-RestMethod -Uri $url
Write-Host "IP: $($host.ip_str)"
Write-Host "Organization: $($host.org)"
Write-Host "OS: $($host.os)"
Write-Host "Country: $($host.country_name)"
Write-Host "Open ports: $($host.ports -join ', ')"
Write-Host ""
Write-Host "Services:"
$host.data | ForEach-Object {
Write-Host " Port $($_.port)/$($_.transport) — $($_.product) $($_.version)"
}$query = [Uri]::EscapeDataString("port:27017 product:MongoDB")
$key = $env:SHODAN_API_KEY
$url = "https://api.shodan.io/shodan/host/search?query=${query}&key=${key}"
$results = Invoke-RestMethod -Uri $url
Write-Host "Total results: $($results.total)"
$results.matches | Select-Object -First 10 | ForEach-Object {
Write-Host " $($_.ip_str):$($_.port) — $($_.org) ($($_.location.country_name))"
}$ip = "TARGET_IP"
$key = $env:SHODAN_API_KEY
$host = Invoke-RestMethod -Uri "https://api.shodan.io/shodan/host/${ip}?key=${key}"
if ($host.vulns) {
Write-Host "CVEs found on ${ip}:"
$host.vulns.PSObject.Properties | ForEach-Object { Write-Host " $($_.Name)" }
} else {
Write-Host "No known CVEs found for ${ip}"
}port:22 country:IN SSH servers in India
product:nginx version:1.14 Specific nginx version
org:"Amazon" Amazon-owned IPs
ssl.cert.subject.cn:*.example.com Certs for a domain
http.title:"Dashboard" port:80 Web dashboards on port 80
vuln:CVE-2021-44228 Log4Shell vulnerable hosts"What is exposed on IP 1.2.3.4?" → Use the host lookup. Shows open ports, services, OS.
"Find all MongoDB servers with no auth"
→ Query: port:27017 product:MongoDB -authentication
"Search for Apache servers in India"
→ Query: product:Apache country:IN
"Does this IP have any known CVEs?" → Use the CVE snippet above on the target IP.
Start-Sleep -Milliseconds 1100 between bulk callsvulns field only appears when Shodan has matched CVE data to the service bannerSHODAN_API_KEY — free account at https://account.shodan.io© taracodlabs, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files in skills/shodan of taracodlabs/aiden.
Open the folder on GitHubat commit 3704204
Shodan next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Shodan this skilltaracodlabs/aiden | 851 | — | ~954 | Automated safety check: Pass | Apache-2.0 | |
| Metabigor OSINT Reconj3ssie/metabigor | 1.9k | — | ~2.4k | Automated safety check: Pass | MIT | |
| Ctf Osintljagiello/ctf-skills | 3.4k | 2 repos | ~2.3k | Automated safety check: Notes | MIT | |
| ShadowBroker Intelligence ClientBigBodyCobain/Shadowbroker | 11k | — | ~8.9k | Automated safety check: Warn | AGPL-3.0 | |
| Awesome Osint Operatorshoyann/RZK-The-Hunter | 140 | — | ~4.8k | Automated safety check: Pass | CC-BY-SA-4.0 | |
| Run Claude Osintelementalsouls/Claude-OSINT | 2.8k | — | ~1.2k | Automated safety check: Pass | MIT |
j3ssie/metabigor
Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys.
ljagiello/ctf-skills
Provides open source intelligence techniques for CTF challenges.
BigBodyCobain/Shadowbroker
Lets an agent query a ShadowBroker OSINT platform for tracked flights, ships, satellites and news, and place its findings on the map as intel pins.
shoyann/RZK-The-Hunter
Ethical, evidence-first OSINT planning, tool selection, verification, monitoring, reporting, and guarded official wanted/fugitive-person location intelligence using a structured catalog adapted from…
elementalsouls/Claude-OSINT
Build, validate, and run the claude-osint skills repo — check SKILL.md frontmatter, run the secretscan.py and h1reference.py helpers, run sync-skill-content.sh, run the smoke test.
smixs/osint-skill
Conduct deep OSINT research on individuals. An agent skill from smixs/osint-skill.
taracodlabs/aiden
Searches Google Flights for prices, schedules and availability through browser automation with URL-based queries, and stops short of booking.
taracodlabs/aiden
Delegates code generation, editing and explanation tasks to the OpenAI Codex CLI, with commands for interactive, auto-edit, question-only and model-specific runs.
taracodlabs/aiden
Searches Google Hotels through the agent-browser tool for prices, ratings, amenities and availability, building a search URL from the location and dates and reporting a results table.
taracodlabs/aiden
Generates dark-themed architecture, component, data-flow and network diagrams as self-contained HTML and SVG files that open in any browser.
taracodlabs/aiden
Aggregates holdings across Zerodha, Upstox and Angel One and normalizes order parameters into one format, with confirmation required before any routing.
taracodlabs/aiden
Searches arXiv by keyword, category, author or paper ID through its public API and downloads PDFs, with no API key needed.
Categories
Shodan lookups: internet-connected devices, ports, services. An agent skill from taracodlabs/aiden. Shodan is an agent skill from taracodlabs/aiden.
Shodan fits situations like: tasks that involve OSINT.
Run `npx skills add taracodlabs/aiden --skill shodan -a claude-code`. Or copy the skill folder (skills/shodan in taracodlabs/aiden) into .claude/skills/shodan in your project. Claude Code loads it when a task matches its description.
Run `npx skills add taracodlabs/aiden --skill shodan -a codex`. Or copy the skill folder (skills/shodan in taracodlabs/aiden) into .agents/skills/shodan in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add taracodlabs/aiden --skill shodan -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/shodan, .gemini/skills/shodan, .github/skills/shodan and .opencode/skills/shodan in your project.
Going by SKILL.md and its folder, Shodan needs TypeScript for the scripts in its folder and credentials named SHODAN_API_KEY. Our summary lists: Node.js; A credential in SHODAN_API_KEY.
SKILL.md names 2 domains. In commands or code: api.shodan.io; the agent is likely to contact it when it follows the instructions. As links in the text: account.shodan.io. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Shodan is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 954 tokens (SKILL.md is roughly 3.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Shodan: Metabigor OSINT Recon (j3ssie/metabigor, 1.9k stars), Ctf Osint (ljagiello/ctf-skills, 3.4k stars), ShadowBroker Intelligence Client (BigBodyCobain/Shadowbroker, 11k stars) and Awesome Osint Operator (shoyann/RZK-The-Hunter, 140 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
taracodlabs (a GitHub organization) maintains it in taracodlabs/aiden, which has 851 GitHub stars. The repository holds 63 skills in this directory. The repository was last updated on September 13, 2026.
Source: taracodlabs/aiden on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.