elementalsouls/Claude-OSINT: 10 Agent Skills
8 Claude skills · 100+ recon capabilities · 80 secret-regex patterns · 80+ dorks · 9 read-only credential validators · 27 attack-path templates · ~10,000 lines of structured tradecraft. Drop-in SKILL.md files that turn Claude into a god-mode external recon operator for authorized red-team and…
| Repository | elementalsouls/Claude-OSINT |
|---|---|
| GitHub stars | 2,791 |
| Skills | 10 |
| Category | DevOps, cloud and security |
| License | MIT |
| Last updated | Aug 30, 2026 |
| Install counts | elementalsouls/Claude-OSINT on skills.sh, Vercel's skills directory, which shows installs and security audits per skill |
Install elementalsouls/Claude-OSINT
| All skills, any agent | npx skills add elementalsouls/Claude-OSINT |
|---|---|
| One skill | npx skills add elementalsouls/Claude-OSINT --skill run-claude-osint |
| Only for Claude Code | npx skills add elementalsouls/Claude-OSINT -a claude-code, or copy a skill folder to ~/.claude/skills/ (all projects) or .claude/skills/ (one project) |
npx skills is the open-source skills CLI; it asks which agents to install for. Skills can include scripts that your agent will run: read a skill before installing it, as you would any code.
Skills in elementalsouls/Claude-OSINT
| Skill | What it does |
|---|---|
| run-claude-osint | Build, validate, and run the claude-osint skills repo — check SKILL.md frontmatter, run the secret_scan.py and h1_reference.py helpers, run sync-skill-content.sh, run the smoke test. Use when asked to run, build, test, validate, or smoke-test claude-osint or its OSINT skills/scripts. |
| cloud-saas-exposure | Organization-grade cloud and supply-chain attack-surface discovery: S3/GCS/Azure Blob bucket discovery via observed-name mining (CNAME/cert-SAN/Wayback) and bounded two-class permutation (6 prefixes x 15 suffixes on trusted tokens, bounded target-bound expansion on subdomain stems), existence… |
| continuous-exposure-monitoring | Turns one-shot external recon into a continuous monitoring program. Covers the scheduled re-scan-and-diff loop (baseline snapshot -> interval sleep -> re-scan -> asset/finding delta -> threshold-gated webhook alert), the scan-to-scan diff engine (new/removed/changed assets by a tracked-attribute… |
| email-domain-security | Rigorous, defensible email-spoofability verdict and SPF supply-chain risk analysis computed from published DNS alone. Deepens the record-level SPF/DMARC/DKIM/BIMI/MTA-STS/DNSSEC fetch recipes in the offensive-osint arsenal (§16.14) with the reasoning that section doesn't do: a priority-ordered… |
| exposure-risk-quantification | FAIR-aligned exposure quantification: turns a pile of recon findings into a defensible 0-100 + A-F org risk score (Likelihood x Impact, three ownership-aware factors: exposure/threat/impact), an ownership + proof demotion cap so unproven or weakly-owned findings can't inflate the number, a… |
| identity-provider-recon | Organization-grade identity-fabric mapping: tenant/federation fingerprinting and the pre-auth user-ENUMERATION oracle methodology — enumeration and fingerprint only, never credential submission. Covers domain-to-tenant resolution (Microsoft getuserrealm.srf Managed/Federated namespace check, Entra… |
| offensive-osint | Operational arsenal for external red-team and bug-bounty reconnaissance. Concrete wordlists (28 Swagger paths, 13 GraphQL paths, 35 high-risk ports, 6 missing-header findings, 15 always-on HTTP checks, 5 SAML paths, cloud bucket permutations, JS guess-paths, vendor product fingerprints for… |
| org-attack-surface | Org-grade attack-surface mapping: given a company's legal identity, discover its ENTIRE owned internet footprint — corporate family -> owned domains -> owned netblocks/ASN -> live assets — with attribution discipline, not just DNS breadth. The org-first attribution pyramid (legal entity ->… |
| osint-autopilot | End-to-end external OSINT engagement autopilot. Run the FULL osint-methodology pipeline to completion in ONE go for an authorized domain — engagement folder, Stages 1-5 (seed, expansion, enrichment, exposure, convergence), multi-agent per-host content+JS fan-out, headline verification,… |
| osint-methodology | Comprehensive OSINT methodology for external red-team operations and authorized attack-surface assessments. Covers the 6-stage recon pipeline (seed → asset expansion → enrichment → exposure analysis → convergence → operator-armed active validation) with connector-resilience and stage-vs-gating… |
Names and descriptions come from each skill's SKILL.md and are written by the pack's authors.
More devops, cloud and security skill packs
| # | Skill pack | Skills | GitHub stars | Updated |
|---|---|---|---|---|
| 1 |
vercel-labs/agent-skills Vercel's official collection of agent skills
|
9 | 32.1K | 2026-08-28 |
| 2 |
microsoft/SkillOpt SkillOpt is a text-space optimizer that trains reusable natural-language skills for frozen LLM agents through trajectory-driven e…
|
5 | 18.1K | 2026-10-06 |
| 3 |
SnailSploit/Claude-Red claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SK…
|
79 | 7,352 | 2026-09-19 |
| 4 |
elementalsouls/Claude-BugHunter A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patter…
|
83 | 4,807 | 2026-10-08 |
| 5 |
ljagiello/ctf-skills Agent skills for solving CTF challenges - web exploitation, binary pwn, crypto, reverse engineering, forensics, OSINT, and more
|
11 | 3,411 | 2026-09-13 |
| 6 |
microsoft/skills Skills, MCP servers, Custom Agents, Agents.md for SDKs to ground Coding Agents
|
205 | 3,094 | 2026-10-08 |