offensive-osint

Routes public reconnaissance signals into evidence-backed leads for authorized security assessments.

4|Updated Apr 29, 2026
One-click install
npx skills add https://github.com/Ap6pack/outrider-recon --skill offensive-osint-ap6pack
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: offensive-osint
Source: https://github.com/Ap6pack/outrider-recon/tree/main/skills/offensive-osint
Command: npx skills add https://github.com/Ap6pack/outrider-recon --skill offensive-osint-ap6pack

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) components.

What problem does it solve?

This Skill turns scattered public reconnaissance signals into prioritized, evidence-backed leads for authorized security assessments, reducing the time spent deciding what matters and where to investigate next.

Core Features & Use Cases

  • Task Routing: Delegates recon work across asset discovery, web surfaces, identity and SSO, secrets, cloud infrastructure, people and breach intelligence, and reporting workflows.
  • Evidence-Aware Analysis: Applies scoring rubrics, attack-path hints, severity guidance, and structured run-contract controls to keep observations traceable and properly scoped.
  • Read-Only Recon Support: Provides safe helpers for secret-pattern scanning and HackerOne disclosure research without destructive probing or unauthorized escalation.
  • Use Case: During an authorized bug-bounty engagement, use the Skill to route subdomain discovery, review exposed secrets with read-only validation, compare likely attack paths against public disclosures, and prepare a report-ready candidate.

Quick Start

Use the offensive OSINT skill to begin an authorized external reconnaissance engagement, identify the current pipeline stage, and route the task to the appropriate sub-skill.

Frequently Asked Questions about offensive-osint

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I prioritize external reconnaissance leads for authorized bug bounty engagements?

To prioritize external reconnaissance leads, you can route scattered public signals into structured run contracts that apply scoring rubrics and attack-path hints. This process transforms raw asset discovery data into evidence-backed candidates for your bug bounty reports.

What is the best way to validate exposed secrets during attack surface management without active probing?

Validating exposed secrets during attack surface management requires read-only validation techniques. The system provides safe helpers for secret-pattern scanning that confirm findings without destructive probing or unauthorized escalation, ensuring your external reconnaissance remains non-intrusive.

How does evidence-backed analysis work for external red-team asset discovery?

Evidence-backed analysis for external red-team asset discovery works by attaching unique evidence IDs and severity guidance to each public signal. This ensures your web enumeration observations are traceable and properly scoped for safe handoffs.

Can I use this for HackerOne disclosure research and breach intelligence gathering?

Yes, you can use this for HackerOne disclosure research and breach intelligence gathering. It routes recon tasks across identity analysis and public disclosures, comparing likely attack paths against known breaches while maintaining policy-gated execution.

Do I need explicit authorization controls to run cloud infrastructure OSINT tasks?

Yes, you need explicit authorization controls to run cloud infrastructure OSINT tasks. The system requires scope validation and policy-gated execution to ensure all external reconnaissance and identity analysis remains within authorized boundaries.

Why should I use structured run contracts for security reporting workflows?

You should use structured run contracts for security reporting workflows because they enforce scope controls and attach evidence IDs to observations. This keeps your attack surface management findings traceable and ready for report-ready candidate generation.