offensive-osint

Index probes, wordlists, and regex patterns for authorized external reconnaissance.

3|1|Updated Jul 2, 2026
One-click install
npx skills add https://github.com/EntroVyx/hermes-agent-offsec --skill offensive-osint-entrovyx
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: offensive-osint
Source: https://github.com/EntroVyx/hermes-agent-offsec/tree/main/skills/offsec/redteam/offensive-osint
Command: npx skills add https://github.com/EntroVyx/hermes-agent-offsec --skill offensive-osint-entrovyx

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill provides a structured, operational arsenal for authorized external red-team and bug-bounty reconnaissance, solving the problem of fragmented or disorganized recon workflows.

Core Features & Use Cases

  • Concrete Recon Arsenal: Access pre-built wordlists, regex patterns, and probe paths for subdomain enumeration, cloud bucket discovery, and identity fabric analysis.
  • Severity Scoring: Utilize standardized rubrics for endpoint interest and mobile app ownership to prioritize findings.
  • Use Case: When performing an authorized external assessment, use this Skill to systematically probe for exposed CI/CD pipelines, leaked secrets, or misconfigured cloud buckets while maintaining a consistent severity-scoring methodology.

Quick Start

Use the offensive-osint skill to perform an external reconnaissance scan on target.com and identify potential misconfigurations.

Frequently Asked Questions about offensive-osint

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform external reconnaissance for red-team operations?

External reconnaissance involves probing target surfaces like web, cloud, and mobile assets. This skill provides pre-built wordlists, regex patterns, and probe paths to systematically discover subdomains, exposed CI/CD pipelines, and misconfigured cloud buckets during authorized assessments.

What is the best way to prioritize bug-bounty findings during asset discovery?

Prioritizing bug-bounty findings requires standardized rubrics for endpoint interest and mobile app ownership. This skill provides severity scoring methodologies to triage discovered secrets and misconfigurations, ensuring consistent evaluation across web and cloud surfaces.

Can I use this skill to enumerate cloud buckets and leaked secrets?

Yes, you can enumerate cloud buckets and triage leaked secrets. The skill supplies operational reference files containing specific probe paths and regex patterns designed to identify exposed cloud storage and sensitive credentials across authorized external targets.

Do I need specific authorization to run red-team reconnaissance probes?

Yes, strict authorization is required. The skill is designed exclusively for authorized external red-team and bug-bounty reconnaissance, adhering to legal posture guidelines to ensure all asset discovery, identity fabric enumeration, and probing activities remain compliant.

How do I execute specific reconnaissance tasks like identity fabric enumeration?

You execute specific reconnaissance tasks by modularly loading the appropriate reference files. The skill supports targeted operations like identity fabric analysis by providing structured probes and regex patterns that must be loaded to perform the selected scan.

What limitations exist when using pre-built wordlists for subdomain enumeration?

Pre-built wordlists are limited to discovering assets matching known patterns and require valid authorization. This skill provides structured probe paths for subdomain enumeration but cannot find unlisted assets outside its wordlist scope or bypass external access controls.