Skip to content
Agents tracked: 283 Downloads (7d): 261M up 5.8% GitHub stars: 6.2M VS Code installs: 151M Releases (7d): 289 Agent status: 1 with issues Updated Oct 9, 2026

elementalsouls/Claude-OSINT: 10 Agent Skills

8 Claude skills · 100+ recon capabilities · 80 secret-regex patterns · 80+ dorks · 9 read-only credential validators · 27 attack-path templates · ~10,000 lines of structured tradecraft. Drop-in SKILL.md files that turn Claude into a god-mode external recon operator for authorized red-team and…

Repositoryelementalsouls/Claude-OSINT
GitHub stars2,791
Skills10
CategoryDevOps, cloud and security
LicenseMIT
Last updatedAug 30, 2026
Install countselementalsouls/Claude-OSINT on skills.sh, Vercel's skills directory, which shows installs and security audits per skill

Install elementalsouls/Claude-OSINT

All skills, any agentnpx skills add elementalsouls/Claude-OSINT
One skillnpx skills add elementalsouls/Claude-OSINT --skill run-claude-osint
Only for Claude Codenpx skills add elementalsouls/Claude-OSINT -a claude-code, or copy a skill folder to ~/.claude/skills/ (all projects) or .claude/skills/ (one project)

npx skills is the open-source skills CLI; it asks which agents to install for. Skills can include scripts that your agent will run: read a skill before installing it, as you would any code.

Skills in elementalsouls/Claude-OSINT

SkillWhat it does
run-claude-osintBuild, validate, and run the claude-osint skills repo — check SKILL.md frontmatter, run the secret_scan.py and h1_reference.py helpers, run sync-skill-content.sh, run the smoke test. Use when asked to run, build, test, validate, or smoke-test claude-osint or its OSINT skills/scripts.
cloud-saas-exposureOrganization-grade cloud and supply-chain attack-surface discovery: S3/GCS/Azure Blob bucket discovery via observed-name mining (CNAME/cert-SAN/Wayback) and bounded two-class permutation (6 prefixes x 15 suffixes on trusted tokens, bounded target-bound expansion on subdomain stems), existence…
continuous-exposure-monitoringTurns one-shot external recon into a continuous monitoring program. Covers the scheduled re-scan-and-diff loop (baseline snapshot -> interval sleep -> re-scan -> asset/finding delta -> threshold-gated webhook alert), the scan-to-scan diff engine (new/removed/changed assets by a tracked-attribute…
email-domain-securityRigorous, defensible email-spoofability verdict and SPF supply-chain risk analysis computed from published DNS alone. Deepens the record-level SPF/DMARC/DKIM/BIMI/MTA-STS/DNSSEC fetch recipes in the offensive-osint arsenal (§16.14) with the reasoning that section doesn't do: a priority-ordered…
exposure-risk-quantificationFAIR-aligned exposure quantification: turns a pile of recon findings into a defensible 0-100 + A-F org risk score (Likelihood x Impact, three ownership-aware factors: exposure/threat/impact), an ownership + proof demotion cap so unproven or weakly-owned findings can't inflate the number, a…
identity-provider-reconOrganization-grade identity-fabric mapping: tenant/federation fingerprinting and the pre-auth user-ENUMERATION oracle methodology — enumeration and fingerprint only, never credential submission. Covers domain-to-tenant resolution (Microsoft getuserrealm.srf Managed/Federated namespace check, Entra…
offensive-osintOperational arsenal for external red-team and bug-bounty reconnaissance. Concrete wordlists (28 Swagger paths, 13 GraphQL paths, 35 high-risk ports, 6 missing-header findings, 15 always-on HTTP checks, 5 SAML paths, cloud bucket permutations, JS guess-paths, vendor product fingerprints for…
org-attack-surfaceOrg-grade attack-surface mapping: given a company's legal identity, discover its ENTIRE owned internet footprint — corporate family -> owned domains -> owned netblocks/ASN -> live assets — with attribution discipline, not just DNS breadth. The org-first attribution pyramid (legal entity ->…
osint-autopilotEnd-to-end external OSINT engagement autopilot. Run the FULL osint-methodology pipeline to completion in ONE go for an authorized domain — engagement folder, Stages 1-5 (seed, expansion, enrichment, exposure, convergence), multi-agent per-host content+JS fan-out, headline verification,…
osint-methodologyComprehensive OSINT methodology for external red-team operations and authorized attack-surface assessments. Covers the 6-stage recon pipeline (seed → asset expansion → enrichment → exposure analysis → convergence → operator-armed active validation) with connector-resilience and stage-vs-gating…

Names and descriptions come from each skill's SKILL.md and are written by the pack's authors.

More devops, cloud and security skill packs

All devops, cloud and security skills

# Skill pack Skills GitHub stars Updated
1
vercel-labs/agent-skills Vercel's official collection of agent skills
9 32.1K 2026-08-28
2
microsoft/SkillOpt SkillOpt is a text-space optimizer that trains reusable natural-language skills for frozen LLM agents through trajectory-driven e…
5 18.1K 2026-10-06
3
SnailSploit/Claude-Red claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SK…
79 7,352 2026-09-19
4
elementalsouls/Claude-BugHunter A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patter…
83 4,807 2026-10-08
5
ljagiello/ctf-skills Agent skills for solving CTF challenges - web exploitation, binary pwn, crypto, reverse engineering, forensics, OSINT, and more
11 3,411 2026-09-13
6
microsoft/skills Skills, MCP servers, Custom Agents, Agents.md for SDKs to ground Coding Agents
205 3,094 2026-10-08