What problem does it solve?
This skill solves the problem of fragmented, time-consuming reconnaissance during authorized external red-team and bug-bounty operations. It consolidates field-validated probes, wordlists, regex patterns, and dorks into a single operational index, eliminating hours of manual searching across Shodan, crt.sh, GitHub, and breach databases.
Core Features & Use Cases
- Concrete Probe Arsenal: 28 Swagger/OpenAPI paths, 13 GraphQL paths, 35 high-risk port fingerprints, cloud-bucket permutation generators (S3/GCS/Azure), vendor product fingerprints (Citrix, F5, Pulse, Fortinet, PaloAlto, Cisco, VMware), and CI/CD exposure checks.
- Secret Triage Pipeline: 48-pattern secret catalog with severity ratings, 9 read-only validators for AWS, GitHub, Slack, Postman, JWT, Anthropic, OpenAI, npm, and Atlassian, plus post-discovery enumeration workflows.
- Attack-Surface Scoring: Endpoint interest score (0-100 rubric), mobile app ownership confidence (0-100 rubric), severity decision matrix with 80+ worked examples, and 27 attack-path hint templates.
- Sector & Mass Recon: Sector-specific notes for healthcare, finance, ICS/SCADA, IoT, and government, plus empirical mass-recon methodology for non-regulated US SMB sectors with parallel batch testing and false-positive filtering.
Quick Start
Use the offensive-osint skill to perform external reconnaissance on a target by scanning for subdomains and API endpoints, checking for exposed secrets in JavaScript bundles, and validating any discovered credentials with read-only checks.