offensive-osint

Index probes, wordlists, and regex patterns for external reconnaissance.

13|2|Updated Jun 1, 2026
One-click install
npx skills add https://github.com/pdparchitect/rook --skill offensive-osint-pdparchitect
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: offensive-osint
Source: https://github.com/pdparchitect/rook/tree/main/skills/offensive-osint
Command: npx skills add https://github.com/pdparchitect/rook --skill offensive-osint-pdparchitect

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This skill provides a structured, operational arsenal for authorized external red-team and bug-bounty reconnaissance, eliminating the need to manually curate probes, wordlists, and regex patterns during engagements.

Core Features & Use Cases

  • Reconnaissance Arsenal: Access a comprehensive library of concrete probes, wordlists, and regexes for subdomain enumeration, cloud bucket discovery, and identity fabric mapping.
  • Secret Triage: Utilize a 48-pattern secret-scanning catalog to identify leaked credentials across various platforms like AWS, GitHub, and OpenAI.
  • Use Case: When performing an authorized external audit, use this skill to systematically map an organization's attack surface, identify exposed cloud buckets, and validate potential secret leaks using the provided helper scripts.

Quick Start

Use the offensive-osint skill to perform an external reconnaissance scan on target.com and identify exposed subdomains and cloud buckets.

Frequently Asked Questions about offensive-osint

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I enumerate subdomains and discover exposed cloud buckets during a red-team engagement?

Subdomain enumeration and cloud bucket discovery are supported through a structured library of probes and wordlists, allowing you to systematically map an organization's external attack surface during authorized red-team engagements.

What regex patterns can I use to scan for leaked AWS, GitHub, or OpenAI credentials?

A 48-pattern secret-scanning catalog provides regex patterns to identify leaked credentials across platforms like AWS, GitHub, and OpenAI, utilizing standard library Python scripts to validate potential secret leaks found during reconnaissance.

Do I need any external dependencies to run secret scanning and asset discovery probes?

No external dependencies are required, as the skill relies on standard library Python for secret scanning and modular reference loading to execute task-specific asset discovery and attack-path mapping operations.

Can I use this reconnaissance arsenal for bug bounty and vulnerability research?

Yes, the operational arsenal is explicitly designed for authorized external bug bounty and vulnerability research, providing concrete probes, wordlists, and regex patterns to map attack paths across cloud, identity, and web infrastructure.

What is the best way to map an organization's identity fabric during an external security audit?

Identity fabric mapping is achieved by utilizing the skill's comprehensive operational index of probes, enabling systematic discovery and attack-path mapping across cloud, identity, and web infrastructure targets during security audits.

Are there limitations when using these probes for unauthorized external reconnaissance?

The skill is strictly designed for authorized external red-team and bug-bounty reconnaissance, and its probes, wordlists, and secret triage scripts should not be deployed against targets without explicit permission.