Topic · Security

Best OSINT skills for Claude Code, Codex and other agents.

Skills that gather open-source intelligence for security and investigations.
skills
117
official
2

OSINT skills, ranked

Ranked by score. Sort bymost stars,trending,newest,recently updated

OSINT skills, ranked
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

Guides building Flowsint enrichers and types: where definitions live, how the base class and vault work, and when a new type is warranted.

reconurge/flowsint9.3k—~2.6kAutomated safety check: PassApache-2.04 days ago
2

Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys.

j3ssie/metabigor1.8k—~2.4kAutomated safety check: PassMIT2 mo ago
3

Provides open source intelligence techniques for CTF challenges.

ljagiello/ctf-skills3.4k2 repos~2.3kAutomated safety check: NotesMIT23 days ago
4

Lets an agent query a ShadowBroker OSINT platform for tracked flights, ships, satellites and news, and place its findings on the map as intel pins.

BigBodyCobain/Shadowbroker11k—~8.9kAutomated safety check: WarnAGPL-3.0today
5

Ethical, evidence-first OSINT planning, tool selection, verification, monitoring, reporting, and guarded official wanted/fugitive-person location intelligence using a structured catalog adapted from…

shoyann/RZK-The-Hunter140—~4.8kAutomated safety check: PassCC-BY-SA-4.016 days ago
6

Build, validate, and run the claude-osint skills repo — check SKILL.md frontmatter, run the secretscan.py and h1reference.py helpers, run sync-skill-content.sh, run the smoke test.

elementalsouls/Claude-OSINT2.8k—~1.2kAutomated safety check: PassMIT1 mo ago
7

Conduct deep OSINT research on individuals. An agent skill from smixs/osint-skill.

smixs/osint-skill140—~5.5kAutomated safety check: PassMIT7 mo ago
8

Reference knowledge for open-source intelligence collection: the collection cycle, source reliability tiers, search query patterns and entity extraction.

RightNow-AI/openfang18k—~2.1kAutomated safety check: PassApache-2.03 mo ago
9

Comprehensive OSINT methodology for external red-team operations and authorized attack-surface assessments.

elementalsouls/Claude-OSINT2.8k—~8.7kAutomated safety check: NotesMIT1 mo ago
10

Deep web-research methodology for the interceptor browser surface — investigate a topic the way researchers, intelligence analysts, investigative journalists, private investigators, and OSINT…

Hacker-Valley-Media/Interceptor514—~3.8kAutomated safety check: PassUnknown4 days ago
11

Professional malware analysis workflow for PE executables and suspicious files.

tsale/awesome-dfir-skills324—~2.5kAutomated safety check: PassApache-2.04 mo ago
12

Interact with Microsoft Teams — send and read messages, search conversations, look up people, check calendar, get meeting transcripts, and manage chats.

sigcli/sigcli293—~2.7kAutomated safety check: PassMIT9 days ago
13

Maps the attack surface of a web domain you are authorized to test: confirms scope, lists subdomains from public sources, probes live hosts and fingerprints technology.

PentesterFlow/agent1.4k—~1.2kAutomated safety check: PassApache-2.01 mo ago
14

Enriches IOCs, campaigns, impersonation and scams from public sources, including bounded X search through Xquik, and checks each lead against independent evidence.

zhaoxuya520/reverse-skill40k1 repo~1kAutomated safety check: PassMIT15 days ago
15

Apply the NATO Admiralty System (AJP-2.1) to assess source reliability and information credibility in cyber threat intelligence, OSINT, and breach analysis.

tsale/awesome-dfir-skills324—~3.4kAutomated safety check: PassApache-2.04 mo ago
16

Public-records OSINT investigation framework — SEC EDGAR filings, USAspending contracts, Senate lobbying, OFAC sanctions, ICIJ offshore leaks, NYC property records (ACRIS), OpenCorporates…

johnson7788/MultiUserClaw327—~3kAutomated safety check: PassMIT1 mo ago
17

Analyse Mitre ATT&CK tactics, techniques and sub-techniques.

tsale/awesome-dfir-skills324—~1.4kAutomated safety check: PassApache-2.04 mo ago
18

Enrich an IOC (IP, domain, hash, URL) with threat intelligence.

dandye/ai-runbooks127—~702Automated safety check: PassApache-2.01 mo ago
19

Follow the money via public records and sanctions data. An agent skill from Luciole-Studio/Misaka-Agent.

Luciole-Studio/Misaka-Agent1251 repo~2.9kAutomated safety check: PassMITtoday
20

Build structured threat actor profiles using the 5W1H framework and the Diamond Model.

tsale/awesome-dfir-skills324—~2.8kAutomated safety check: PassApache-2.04 mo ago
21

Get verified emails and phones for contacts found by people-search.

extruct-ai/gtm-skills109—~1.3kAutomated safety check: PassNo licence9 days ago
22

OSINT username search across 400+ social networks. An agent skill from Tommy-yw/RunbookHermes.

Tommy-yw/RunbookHermes5463 repos~1.5kAutomated safety check: PassMIT4 mo ago
23

Run competitive research like an intelligence agency: eight collection disciplines (OSINT to MASINT), signal-to-inference chains, and fusion.

deanpeters/Product-Manager-Skills7.2k—~6.6kAutomated safety check: PassUnknown1 mo ago
24

Passive domain reconnaissance using Python stdlib. An agent skill from Tommy-yw/RunbookHermes.

Tommy-yw/RunbookHermes5461 repo~1.1kAutomated safety check: PassMIT4 mo ago
25

Build an automated IOC enrichment pipeline on OpenCTI (STIX 2.1 native threat intel platform) using its internal enrichment connectors to pull context from VirusTotal, Shodan, AbuseIPDB, and…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.5kAutomated safety check: PassApache-2.01 mo ago
26

Build a systematic threat-hunt workflow that turns threat intelligence and ATT&CK gap analysis into testable hypotheses, then executes and validates them via EDR/SIEM queries (CrowdStrike, Defender…

mukul975/Anthropic-Cybersecurity-Skills34k—~893Automated safety check: PassApache-2.01 mo ago
27

Build automated IOC enrichment pipelines in Splunk Enterprise Security by ingesting threat feeds into KV Store collections and correlating them against security events via lookup tables, modular…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.7kAutomated safety check: PassApache-2.01 mo ago
28

Design and deploy a Threat Intelligence Platform (TIP) by integrating open-source CTI tools (MISP, OpenCTI, TheHive, Cortex) into a unified system with feed ingestion pipelines, enrichment…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.5kAutomated safety check: PassApache-2.01 mo ago
29

Deploy MISP, configure threat feeds (MISP community, freetext, TAXII, CSV), and use the PyMISP API to programmatically fetch, add, and search events and IOCs, building automated collection pipelines…

mukul975/Anthropic-Cybersecurity-Skills34k—~1.6kAutomated safety check: NotesApache-2.01 mo ago
30

Extracts embedded configuration from Agent Tesla RAT samples, including SMTP/FTP/Telegram exfiltration credentials, keylogger settings, and C2 endpoints, via .NET decompilation and memory analysis.

mukul975/Anthropic-Cybersecurity-Skills34k—~1.8kAutomated safety check: PassApache-2.01 mo ago
31

Implements a STIX 2.1/TAXII 2.1 threat-intelligence feed consumer and producer in Python, covering TAXII server discovery, collection polling, parsing STIX bundles with the stix2 library, and…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.7kAutomated safety check: PassApache-2.01 mo ago
32

Configure NextDNS as an encrypted (DoH/DoT) zero trust DNS resolver that blocks malicious, phishing, and cryptojacking domains via real-time threat intelligence, detects DNS rebinding and CNAME…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.8kAutomated safety check: NotesApache-2.01 mo ago
33

Reduces SIEM false positives through systematic rule tuning, threshold adjustment, correlation logic refinement, allowlisting, and threat intelligence enrichment.

mukul975/Anthropic-Cybersecurity-Skills34k—~1.9kAutomated safety check: PassApache-2.01 mo ago
34

Tracks IOCs through discovery, enrichment/validation (VirusTotal, Shodan, passive DNS), deployment to SIEM/IDS watchlists, hit-rate and false-positive monitoring, confidence-score decay, and…

mukul975/Anthropic-Cybersecurity-Skills34k—~1.5kAutomated safety check: PassApache-2.01 mo ago
35

Discovers and maps adversary-controlled infrastructure (C2 servers, phishing domains, exploit-kit hosts, bulletproof hosting) by pivoting across passive DNS, certificate transparency logs…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.9kAutomated safety check: PassApache-2.01 mo ago
36

Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access.

trilwu/secskills156—~3.1kAutomated safety check: NotesMIT1 mo ago
37

Research LinkedIn professional profiles and public business-contact data, including email/phone lookup, people search, and YouTube channel business-email discovery.

sickn33/agentic-awesome-skills47k1 repo~1.2kAutomated safety check: PassMITyesterday
38

Authorized OSINT and cyber threat intelligence: enriching IOCs, campaigns, impersonation, scams, and threat-actor profiles from public sources with defined boundaries.

sickn33/agentic-awesome-skills47k1 repo~1.1kAutomated safety check: PassMITyesterday
39

Safely monitor ransomware group Tor-hosted data leak sites (DLS) to collect and extract structured victim posting data, track group activity trends over time, and produce sector- and…

mukul975/Anthropic-Cybersecurity-Skills34k—~3.6kAutomated safety check: PassApache-2.01 mo ago
40

Traces ransomware cryptocurrency payment flows using blockchain analysis tools such as Chainalysis Reactor, WalletExplorer, and blockchain.com APIs, identifying wallet clusters and tracking fund…

mukul975/Anthropic-Cybersecurity-Skills34k—~1.9kAutomated safety check: PassApache-2.01 mo ago
41

Analyzes structured and unstructured threat intelligence feeds to extract actionable indicators, adversary tactics, and campaign context.

mukul975/Anthropic-Cybersecurity-Skills34k—~1.6kAutomated safety check: PassApache-2.01 mo ago
42

Automates the enrichment of raw indicators of compromise with multi-source threat intelligence context using SOAR platforms, Python pipelines, or TIP playbooks to reduce analyst triage time and…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: PassApache-2.01 mo ago
43

Build an automated adversary infrastructure tracking system in Python (dnspython, python-whois, shodan, networkx) that pivots across passive DNS, certificate transparency logs, WHOIS records, and IP…

mukul975/Anthropic-Cybersecurity-Skills34k—~3.7kAutomated safety check: PassApache-2.01 mo ago
44

Parse cyber threat intelligence reports (Mandiant, CrowdStrike, Talos, Microsoft) with stix2, mitreattack-python, and spaCy to extract adversary behaviors, map them to MITRE ATT&CK technique IDs…

mukul975/Anthropic-Cybersecurity-Skills34k—~3.4kAutomated safety check: PassApache-2.01 mo ago
45

Builds vendor-agnostic detection rules using the Sigma rule format for threat detection across SIEM platforms including Splunk, Elastic, and Microsoft Sentinel.

mukul975/Anthropic-Cybersecurity-Skills34k—~2.7kAutomated safety check: PassApache-2.01 mo ago
46

Build threat actor profiles by collecting OSINT from vendor reports, paste sites, dark web forums, social media, and code repos, correlating indicators, mapping adversary infrastructure with tools…

mukul975/Anthropic-Cybersecurity-Skills34k—~3.8kAutomated safety check: PassApache-2.01 mo ago
47

Deploy MISP via Docker and configure feeds from sources like abuse.ch, AlienVault OTX, and CIRCL to aggregate, correlate, and distribute threat intelligence, including automated feed synchronization…

mukul975/Anthropic-Cybersecurity-Skills34k—~3.2kAutomated safety check: PassApache-2.01 mo ago
48

Builds automated threat intelligence feed integration pipelines connecting STIX/TAXII feeds, open-source threat intel, and commercial TI platforms into SIEM and security tools for real-time IOC…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.8kAutomated safety check: PassApache-2.01 mo ago

Questions, answered from the data.

What is the best OSINT skill?

Flowsint Enricher Builder from reconurge/flowsint ranks first of the 117 OSINT skills listed here, with the highest score: its repository has 9.3k GitHub stars, its SKILL.md loads about 2.6k tokens and it passes the automated safety check with no findings. Next come Metabigor OSINT Recon and Ctf Osint.

Which OSINT skills are official?

2 of the 117 OSINT skills are official, published by the vendor's own GitHub organization: Secops Detection Engineering and Detection Engineering Coverage Evaluation.

How are these skills ranked?

By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.