Metabigor OSINT Recon
j3ssie/metabigor
Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys.
Write security findings and assessment reports — severity scoring with CVSS and business impact, reproducible proof of concept, remediation guidance, executive summaries, and coordinated disclosure.
$ npx skills add trilwu/secskills --skill reporting-security-findings -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install trilwu/secskills reporting-security-findings --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/secskills-core/skills/reporting-security-findings .claude/skills/reporting-security-findings && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "reporting-security-findings" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-core/skills/reporting-security-findings into .claude/skills/reporting-security-findings/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "reporting-security-findings", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/trilwu/secskills/tree/main/secskills-core/skills/reporting-security-findingsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add trilwu/secskills --skill reporting-security-findings -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install trilwu/secskills reporting-security-findings --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/secskills-core/skills/reporting-security-findings .agents/skills/reporting-security-findings && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "reporting-security-findings" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-core/skills/reporting-security-findings into .agents/skills/reporting-security-findings/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "reporting-security-findings", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trilwu/secskills --skill reporting-security-findings -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install trilwu/secskills reporting-security-findings --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/secskills-core/skills/reporting-security-findings .cursor/skills/reporting-security-findings && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "reporting-security-findings" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-core/skills/reporting-security-findings into .cursor/skills/reporting-security-findings/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "reporting-security-findings", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/trilwu/secskills.git --path secskills-core/skills/reporting-security-findings--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add trilwu/secskills --skill reporting-security-findings -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install trilwu/secskills reporting-security-findings --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/secskills-core/skills/reporting-security-findings .gemini/skills/reporting-security-findings && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "reporting-security-findings" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-core/skills/reporting-security-findings into .gemini/skills/reporting-security-findings/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "reporting-security-findings", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install trilwu/secskills reporting-security-findingsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add trilwu/secskills --skill reporting-security-findings -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .github/skills && cp -r skills-src/secskills-core/skills/reporting-security-findings .github/skills/reporting-security-findings && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "reporting-security-findings" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-core/skills/reporting-security-findings into .github/skills/reporting-security-findings/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "reporting-security-findings", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trilwu/secskills --skill reporting-security-findings -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install trilwu/secskills reporting-security-findings --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/secskills-core/skills/reporting-security-findings .opencode/skills/reporting-security-findings && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "reporting-security-findings" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-core/skills/reporting-security-findings into .opencode/skills/reporting-security-findings/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "reporting-security-findings", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
reporting-security-findingsWrite security findings and assessment reports — severity scoring with CVSS and business impact, reproducible proof of concept, remediation guidance, executive summaries, and coordinated disclosure.
Reporting Security Findings is an agent skill from trilwu/secskills. Write security findings and assessment reports — severity scoring with CVSS and business impact, reproducible proof of concept, remediation guidance, executive summaries, and coordinated disclosure. Use when writing up a vulnerability, producing a pentest or audit report, triaging a bug bounty submission, or preparing a disclosure timeline.
Its SKILL.md is about 3.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Prototyping, Bug bounty and Summarization. The repository describes itself as: Transform Claude Code into your personal security engineer. The licence is MIT.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit ca53957. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
curlgitFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
defuddle.mdFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Reporting Security Findings loads about 3.4k tokens when it runs. Until then it costs about 93 tokens; SKILL.md has 1,551 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from trilwu/secskills at commit ca53957, republished under its MIT licence (© trilwu). 1,551 words, ~3,400 tokens.
.claude/skills/reporting-security-findings/SKILL.md (or your agent's skills folder).The report is the product. Findings that are not understood are not fixed, and findings that cannot be reproduced are disputed. Most of the value an assessment creates is destroyed or preserved in the write-up.
maintaining-engagement-state; this
skill consumes that recordresponding-to-incidentsEvery finding answers five questions, in this order:
### F-03 Tenant isolation bypass in report export [High]
**Summary**
An authenticated user of any tenant can export reports belonging to other
tenants by supplying an arbitrary report ID to `GET /api/v2/reports/{id}/export`.
**Impact**
Full read access to other customers' report data, including the financial
figures and contact records those reports contain. Any customer account —
including a self-service trial — is sufficient. This is a cross-tenant
confidentiality breach with likely contractual and regulatory consequences.
**Affected**
`api/handlers/reports.go:214` (`handleExport`), deployed in production as of
commit `a1b2c3d`. Reproduced on staging 2026-07-24 14:02 UTC.
**Reproduction**
1. Authenticate as `trial-user@tenant-a` and obtain a session token.
2. Note your own report ID from `GET /api/v2/reports` (e.g. `1041`).
3. Request a neighbouring ID:
curl -H "Authorization: Bearer $TOKEN" \
https://staging.example.com/api/v2/reports/1042/export -o out.csv
4. `out.csv` contains tenant B's data. Confirmed with IDs 1042, 1043, 1055.
**Root cause**
The handler looks the report up by primary key and checks only that the
session is valid. The tenant scope present on the list endpoint
(`WHERE tenant_id = ?`) is absent from the export query.
**Remediation**
Add the tenant predicate to the export lookup, and enforce it at the data
access layer rather than per handler so new endpoints inherit it:
SELECT ... FROM reports WHERE id = ? AND tenant_id = ?
Then audit the remaining 14 handlers that call `findByID` without a scope —
listed in Appendix B.
**References**
CWE-639, OWASP API1:2023 Broken Object Level AuthorizationRules that make findings act-on-able:
git log --oneline <checkout>..origin/main -- <file>). One
already-patched finding teaches the reader to distrust the rest.Four of the rules above are mechanical enough to check rather than judge. Run them over every finding; each maps to a way reports have actually gone wrong.
When a finding fails one of these, it does not get quietly dropped: it moves to
the candidate worklist with the reason attached, so a later pass knows what
would promote it. See orchestrating-vulnerability-research for how candidates
are graded when a separate critic does the promoting.
CVSS is the common currency, but it scores a vulnerability in the abstract. Score with CVSS, then state business impact separately — engineering prioritizes on the second.
CVSS 4.0 base vector example:
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N → 6.9 MediumThen adjust for reality and say why:
| Factor | Raises priority | Lowers priority |
|---|---|---|
| Exposure | Internet-facing, unauthenticated | Internal only, requires admin |
| Data | Regulated, customer, credentials | Synthetic, public |
| Exploit maturity | Public exploit, active exploitation | Theoretical, complex chain |
| Compensating controls | None | WAF rule, network segmentation, monitoring |
| Blast radius | Cross-tenant, whole fleet | Single account, single record |
A Medium CVSS that breaks tenant isolation for a SaaS product is a P1 regardless of the number. Say that explicitly rather than letting the score argue for you. Conversely, do not inflate scores: a report where everything is Critical gets triaged by ignoring it.
Chained findings: report the components individually and report the chain as its own finding with the chain's severity. The chain is what an attacker does; the components are what engineering fixes.
Scale the PoC to what proves the point:
id=1042 returning another tenant's
row proves the bug. Dumping the full database does not prove it harder.For memory-safety and exploitation findings, a crash with a controlled instruction pointer plus an analysis of exploitability is usually the right depth. A weaponized exploit belongs in the report only when the engagement explicitly calls for it.
1. Executive summary — 1 page, no jargon, answers "how bad and what now"
2. Scope and methodology — what was tested, how, and with what access
3. Coverage and limitations — what was NOT tested, and why
4. Findings — ordered by severity, each self-contained
5. Strategic recommendations— themes across findings, not per-finding fixes
6. Appendices — tooling, raw output, evidence index, retest resultsThe executive summary is written for someone who will read only it. Three things: the overall risk position in a sentence, the two or three findings that matter, and what decision is being asked for. No CVSS vectors, no tool names, no "we ran Nessus."
Coverage and limitations is the section that protects everyone. State the time box, the accounts and environments you had, the components you could not reach, and the testing you were asked not to do. A report silent on limitations implies coverage it did not have, and that silence is what turns a missed bug into a dispute.
Strategic recommendations are where an assessment earns repeat work: the themes. "Authorization is enforced per handler rather than at the data layer; 9 of 14 findings share this root cause." That sentence is worth more than the nine findings.
| Reader | Wants | Give them |
|---|---|---|
| Executive | Risk and decision | One page, plain language, business consequence |
| Engineering manager | Prioritization and effort | Severity, root cause, scope of the fix |
| Engineer | To fix it today | Exact location, reproduction, concrete change |
| Compliance/audit | Evidence and mapping | Methodology, coverage statement, framework refs |
Write the finding for the engineer, and the summary for the executive. Do not average the two into prose that serves neither.
Tone: describe the defect, not the developer. "The export handler omits the tenant predicate" — not "the developer forgot." Reports circulate, and an accusatory report makes the next engagement harder.
For findings in software you do not own:
Day 0 Report privately: security.txt, /security, GitHub advisory, CERT
Day 0-7 Acknowledge receipt; agree a timeline
Day 45 Check in; offer help reproducing
Day 90 Standard public disclosure deadline (adjust for severity and
exploitation in the wild — actively exploited issues warrant faster
public warning; complex fixes may warrant an extension you agree to)For bug bounty submissions, read the program's scope and rules first, report one issue per submission, and include the impact statement the triager needs to justify the payout internally.
Fetch public advisories, specifications, and vendor reports as Markdown:
curl -sL "https://defuddle.md/<url>" # scheme in the path is optionalThis strips page boilerplate — roughly 78% fewer tokens on a prose page — and returns the full text rather than a summary, so you can grep it and trust a negative result.
Three things it is not for. Fetch JSON and API responses raw, because readability extraction mangles structured data. Fetch authenticated or JavaScript-rendered pages directly, because it retrieves them anonymously. And never route adversary infrastructure (phishing links, C2, malware hosting), client-owned hosts, or engagement URLs through it — the request leaves your machine to a third party, and for live adversary infrastructure it also tips off the operator.
Some sites block the extractor and return an error blob rather than the page —
{"error":"Failed to fetch: 418 I'm a teapot"} from freedesktop.org, for
instance. That is the fetch being refused, not the source saying the thing
does not exist. Re-fetch the URL directly before drawing any conclusion from
it.
auditing-code-for-vulnerabilities — the audit-side deliverable formatresponding-to-incidents — incident narratives and postmortems© trilwu, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in secskills-core/skills/reporting-security-findings of trilwu/secskills.
Open the folder on GitHubat commit ca53957
Reporting Security Findings next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Reporting Security Findings this skilltrilwu/secskills | 157 | — | ~3.4k | Automated safety check: Pass | MIT | |
| Metabigor OSINT Reconj3ssie/metabigor | 1.9k | — | ~2.4k | Automated safety check: Pass | MIT | |
| Wooyun Legacytanweai/wooyun-legacy | 1.8k | — | ~1.9k | Automated safety check: Pass | Custom licence | |
| Client Request Signature Reversalawarexone/Agentic-Bug-Hunter | 5.3k | — | ~4.7k | Automated safety check: Pass | MIT | |
| Web3 Bug Bounty AI Toolstradecatlabs/vibe-coding-cn | 17k | 2 repos | ~3.9k | Automated safety check: Warn | MIT | |
| Penetration Flowlingbol088-spec/ReiPenFlow | 222 | — | ~1.8k | Automated safety check: Pass | MIT |
j3ssie/metabigor
Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys.
tanweai/wooyun-legacy
WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…
awarexone/Agentic-Bug-Hunter
Recovers a client-side request signature or anti-bot token just far enough to replay blocked requests in bug bounty testing, starting from a captured packet.
tradecatlabs/vibe-coding-cn
A selection guide to AI-driven tools for Web3 bug bounty work, from autonomous web pentesters to smart contract bug finders, with notes on authorization.
lingbol088-spec/ReiPenFlow
Guided workflow for authorized penetration testing, vulnerability validation, security reporting, CTF/local sandbox reverse engineering, and user-directed vulnerability research.
samugit83/redamon
Adding partial-recon support for a tool: running a single pipeline phase on demand from the workflow graph, reading its inputs from the existing Neo4j graph and merging results back.
trilwu/secskills
Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.
trilwu/secskills
Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access.
trilwu/secskills
Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…
trilwu/secskills
Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.
trilwu/secskills
Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…
trilwu/secskills
Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…
Categories
Write security findings and assessment reports — severity scoring with CVSS and business impact, reproducible proof of concept, remediation guidance, executive summaries, and coordinated disclosure. Reporting Security Findings is an agent skill from trilwu/secskills. Write security findings and assessment reports — severity scoring with CVSS and business impact, reproducible proof of concept, remediation guidance, executive summaries, and coordinated disclosure.
Reporting Security Findings fits situations like: writing up a vulnerability; producing a pentest; triaging a bug bounty submission; preparing a disclosure timeline.
Run `npx skills add trilwu/secskills --skill reporting-security-findings -a claude-code`. Or copy the skill folder (secskills-core/skills/reporting-security-findings in trilwu/secskills) into .claude/skills/reporting-security-findings in your project. Claude Code loads it when a task matches its description.
Run `npx skills add trilwu/secskills --skill reporting-security-findings -a codex`. Or copy the skill folder (secskills-core/skills/reporting-security-findings in trilwu/secskills) into .agents/skills/reporting-security-findings in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trilwu/secskills --skill reporting-security-findings -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/reporting-security-findings, .gemini/skills/reporting-security-findings, .github/skills/reporting-security-findings and .opencode/skills/reporting-security-findings in your project.
Going by SKILL.md and its folder, Reporting Security Findings needs the command-line tools its instructions call (curl and git).
SKILL.md names 1 domain. In commands or code: defuddle.md; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Reporting Security Findings is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.4k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Reporting Security Findings: Metabigor OSINT Recon (j3ssie/metabigor, 1.9k stars), Wooyun Legacy (tanweai/wooyun-legacy, 1.8k stars), Client Request Signature Reversal (awarexone/Agentic-Bug-Hunter, 5.3k stars) and Web3 Bug Bounty AI Tools (tradecatlabs/vibe-coding-cn, 17k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
trilwu (a GitHub user) maintains it in trilwu/secskills, which has 157 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on September 4, 2026.
Source: trilwu/secskills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.