What problem does it solve?
This skill solves the problem of turning time-consuming external reconnaissance into a structured, probe-ready workflow for authorized red-team and bug-bounty asset discovery.
Core Features & Use Cases
- Actionable OSINT recon: Provides concrete probe paths, wordlists, and copy-paste curl one-liners for discovery across web, identity, cloud, and SaaS surfaces.
- Endpoint and surface prioritization: Uses scoring rubrics (e.g., endpoint interest score and mobile ownership confidence) plus severity decision matrices to help operators focus on the highest-yield findings.
- Secret triage support with validation: Includes a secret-pattern catalog and read-only secret validators (plus a local stdlib helper script) to mirror and verify likely credential leaks.
- Evidence-first outputs: Establishes consistent finding fields, evidence hygiene, timestamps, hashing guidance, and rules-of-engagement posture to keep workflows auditable.
Quick Start
Use the offensive-osint skill to generate a prioritized external recon plan for target domain reconnaissance and identify likely OSINT and secret-leak opportunities with evidence-ready artifacts and scoring.