Claude-OSINT
8 Claude skills · 100+ recon capabilities · 80 secret-regex patterns · 80+ dorks · 9 read-only credential validators · 27 attack-path templates · ~10,000 lines of structured tradecraft. Drop-in SKILL.md files that turn Claude into a god-mode external recon operator for authorized red-team and bug-bo
Claude-OSINT is a comprehensive library of agent skills that transforms Claude into an expert external reconnaissance operator for authorized red-team engagements and bug bounty programs. The collection includes eight structured SKILL.md files totaling approximately 10,000 lines of security tradecraft, covering methodology, tactical arsenal, organizational attack surface mapping, email security analysis, risk quantification, continuous monitoring, cloud exposure detection, and identity provider reconnaissance. Each skill primes Claude with expert-level procedures, regex patterns, tool references, and severity rubrics for different aspects of offensive security research. Developers drop the SKILL.md files into Claude's skills directory to enable automatic activation based on context-relevant phrases during security assessments.
Key Features
Use Cases
- 01Conducting external attack surface assessments for authorized penetration testing engagements
- 02Bug bounty reconnaissance to identify security exposures in web applications and cloud infrastructure
- 03Mapping organizational digital footprints from legal entities to owned IP ranges and domains
- 04Discovering leaked credentials, API keys, and secrets across public repositories and exposed endpoints
- 05Analyzing email security configurations for spoofability and SPF supply-chain vulnerabilities
- 06Quantifying security exposure risk using FAIR methodology for executive reporting
Related Skills
View moresuperpowers
An agentic skills framework & software development methodology that works.
skills
Skills for Real Engineers. Straight from my .agents directory.
skills
Public repository for Agent Skills
ponytail
Makes your AI agent think like the laziest senior dev in the room. The best code is the code you never wrote.
Claude-OSINT — FAQ
What is Claude-OSINT?+
Claude-OSINT is a library of eight agent skills that enhance Claude's capabilities for offensive security reconnaissance and open-source intelligence gathering during authorized security assessments, red-team operations, and bug bounty programs.
How do I install Claude-OSINT skills?+
Clone the repository, run the sync script, then copy the skills directory contents to ~/.claude/skills/. For Claude Code, the skills auto-load in sessions. For other Claude interfaces, paste SKILL.md contents into the project system prompt or prepend to conversations.
Which AI clients work with these skills?+
These skills are designed for Claude Code (with automatic skill loading), Claude Desktop, Claude.ai web interface, and Claude API. They can be manually adapted for other AI assistants by using the SKILL.md files as system prompts or reference documentation.
Do I need API keys or special credentials?+
The skills themselves don't require API keys to load, but many of the reconnaissance techniques they reference involve third-party OSINT tools and services that may require their own API keys or authentication for full functionality.
Is Claude-OSINT free to use?+
Yes, the repository is dual-licensed as MIT for code and CC BY 4.0 for content, allowing free use including commercial applications with proper attribution to Sachin Sharma and the Claude-OSINT project.
What are the authorization requirements?+
These skills are intended only for assets you own or have written authorization to assess, such as red-team rules of engagement, bug bounty in-scope targets, or ASM contracts. The skills include scope-checking prompts and explicitly exclude active exploitation or credential submission.
How do I install Claude-OSINT?+
Open the source repository on GitHub and follow its README. Claude-OSINT is a skill — MCP Agents Market links you directly to the official repo.
Is Claude-OSINT free?+
Claude-OSINT is an open-source project hosted on GitHub. Check the repository for its license and any usage requirements.