What problem does it solve?
This Skill turns scattered public reconnaissance signals into prioritized, evidence-backed leads for authorized security assessments, reducing the time spent deciding what matters and where to investigate next.
Core Features & Use Cases
- Task Routing: Delegates recon work across asset discovery, web surfaces, identity and SSO, secrets, cloud infrastructure, people and breach intelligence, and reporting workflows.
- Evidence-Aware Analysis: Applies scoring rubrics, attack-path hints, severity guidance, and structured run-contract controls to keep observations traceable and properly scoped.
- Read-Only Recon Support: Provides safe helpers for secret-pattern scanning and HackerOne disclosure research without destructive probing or unauthorized escalation.
- Use Case: During an authorized bug-bounty engagement, use the Skill to route subdomain discovery, review exposed secrets with read-only validation, compare likely attack paths against public disclosures, and prepare a report-ready candidate.
Quick Start
Use the offensive OSINT skill to begin an authorized external reconnaissance engagement, identify the current pipeline stage, and route the task to the appropriate sub-skill.