offensive-osint

Generate probe paths, wordlists, and evidence-scoped findings for authorized asset discovery.

1|Updated Apr 18, 2026
One-click install
npx skills add https://github.com/jellaharshith/SWIFT --skill offensive-osint-jellaharshith
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: offensive-osint
Source: https://github.com/jellaharshith/SWIFT/tree/main/swift/skills/cbh/skills/offensive-osint
Command: npx skills add https://github.com/jellaharshith/SWIFT --skill offensive-osint-jellaharshith

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) and scripts (resource) components.

What problem does it solve?

This skill solves the problem of turning time-consuming external reconnaissance into a structured, probe-ready workflow for authorized red-team and bug-bounty asset discovery.

Core Features & Use Cases

  • Actionable OSINT recon: Provides concrete probe paths, wordlists, and copy-paste curl one-liners for discovery across web, identity, cloud, and SaaS surfaces.
  • Endpoint and surface prioritization: Uses scoring rubrics (e.g., endpoint interest score and mobile ownership confidence) plus severity decision matrices to help operators focus on the highest-yield findings.
  • Secret triage support with validation: Includes a secret-pattern catalog and read-only secret validators (plus a local stdlib helper script) to mirror and verify likely credential leaks.
  • Evidence-first outputs: Establishes consistent finding fields, evidence hygiene, timestamps, hashing guidance, and rules-of-engagement posture to keep workflows auditable.

Quick Start

Use the offensive-osint skill to generate a prioritized external recon plan for target domain reconnaissance and identify likely OSINT and secret-leak opportunities with evidence-ready artifacts and scoring.

Frequently Asked Questions about offensive-osint

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I generate a probe-ready external reconnaissance plan for subdomain and endpoint discovery?

External reconnaissance planning translates authorized target domains into concrete probe paths, wordlists, and copy-paste curl one-liners for subdomain and endpoint discovery. You receive a structured, evidence-scoped workflow that prioritizes high-yield findings for asset discovery.

What is the best way to identify exposed secrets and validate credential leaks during an OSINT operation?

Secret identification during OSINT uses a secret-pattern catalog with regex coverage to locate likely credential leaks. Read-only secret validators and a local stdlib helper script mirror and verify these exposed credentials without modifying external assets.

How does severity scoring work for vulnerability and takeover reconnaissance findings?

Severity scoring for takeover reconnaissance uses scoring rubrics like endpoint interest score and mobile ownership confidence combined with severity decision matrices. This scoring helps operators focus on the highest-yield findings and prioritize asset discovery targets.

How do I enumerate identity-fabric endpoints and SaaS public surfaces for bug bounty targets?

Identity-fabric endpoint enumeration and SaaS public-surface hunting map external identities and exposed SaaS applications. This process generates structured probe paths and wordlists to discover unauthorized access points for bug bounty asset discovery.

Can I use this approach to discover swagger, openapi, and graphql endpoints on external targets?

Swagger, OpenAPI, and GraphQL discovery on external targets translates reconnaissance questions into specific probe paths and wordlists. This structured approach yields evidence-scoped findings that fit a guided recon and severity scoring pipeline.

What output formats and evidence hygiene conventions are needed for auditable red-team recon?

Auditable red-team recon requires consistent finding fields, evidence hygiene standards, timestamps, and hashing guidance. These output conventions maintain rules-of-engagement posture and ensure workflows remain structured and verifiable for external asset discovery.