people-breach-intel

Prioritize breach exposure and identity signals for authorized external reconnaissance.

4|Updated Apr 29, 2026
One-click install
npx skills add https://github.com/Ap6pack/outrider-recon --skill people-breach-intel
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: people-breach-intel
Source: https://github.com/Ap6pack/outrider-recon/tree/main/skills/people-breach-intel
Command: npx skills add https://github.com/Ap6pack/outrider-recon --skill people-breach-intel

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill helps authorized security teams turn breach intelligence, exposed identities, leaked packages, and public collaboration signals into prioritized, evidence-backed recon leads without treating recon as exploitation.

Core Features & Use Cases

  • Breach and Infostealer Intelligence: Query HudsonRock, HIBP, DeHashed, and related sources to assess domain-level exposure and identify compromised employee or customer accounts.
  • People and Exposure Discovery: Infer email patterns, harvest publicly exposed addresses, discover Slack and Discord workspaces, and correlate identities with SSO exposure.
  • Leak and Vulnerability Prioritization: Scan historical package versions for secrets, identify typosquat risks, and score CVEs using KEV, EPSS, PoC, exploitation, and severity signals.
  • Use Case: For an authorized engagement, investigate a company domain, identify compromised employee accounts and undocumented portals, prioritize associated CVEs, and produce evidence-linked finding candidates for human review.

Quick Start

Use the people-breach-intel skill to assess breach exposure for the authorized domain example.com and return prioritized findings with evidence IDs.

Frequently Asked Questions about people-breach-intel

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I prioritize breach intelligence and identity exposure for authorized external reconnaissance?

To prioritize breach intelligence for authorized external reconnaissance, you query sources like HudsonRock, HIBP, and DeHashed to assess domain exposure and identify compromised accounts. This process turns raw breach data into evidence-backed recon leads for human review.

What is the best way to discover email patterns and SSO exposure during an engagement?

The best way to discover email patterns and SSO exposure is by inferring email formats, harvesting publicly exposed addresses, and correlating those identities with SSO exposure. This approach maps human identities to authentication surfaces for authorized security teams.

How do I scan leaked packages and historical versions for exposed secrets?

To scan leaked packages for exposed secrets, you scan historical package versions for sensitive data, identify typosquat risks, and correlate findings with supply-chain leak hunting. This ensures leaked package intelligence is prioritized safely without treating recon as exploitation.

Can I use breach intelligence to score CVEs using KEV, EPSS, and PoC exploitation signals?

Yes, you can use breach intelligence to score CVEs using KEV, EPSS, PoC, exploitation, and severity signals. This vulnerability prioritization evaluates historical package versions and public collaboration signals to produce evidence-linked finding candidates.

Does people-based recon require artifact hashing and privacy safeguards before finding validation?

Yes, people-based recon requires artifact hashing, scope and approval controls, privacy safeguards, and human review before finding validation. These controls ensure external reconnaissance and identity correlation remain authorized and evidence-linked throughout the assessment.