CtrlK
BlogDocsLog inGet started
Tessl Logo

osint

Open-source intelligence gathering — email harvesting, social media profiling, breach data checking, employee enumeration, GitHub secret scanning, organizational mapping.

57

Quality

66%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/standard/recon/osint/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

65%Weight 40%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is highly actionable with concrete executable commands and a clear section structure, but it is a monolithic file with no progressive disclosure and lacks validation checkpoints in its workflow. Splitting reference material into bundle files and adding verification steps would improve it.

Suggestions

Add explicit validation/verification checkpoints to the OSINT workflow (Section 8), e.g., confirm scope/authorization before each data-source query and verify harvested data against a second source.

Split the large reference catalogs (API commands, Google dorks, output file spec) into bundle files under references/ and link to them from SKILL.md to apply progressive disclosure.

Trim conceptual padding such as the opening definition paragraph; assume Claude knows what OSINT is and keep only operational guidance.

DimensionReasoningScore

Conciseness

The body is largely a lean reference catalog of commands and dorks, but it includes some mild padding (e.g., the opening 'OSINT collects publicly available information...' and several prose explanation points) that could be tightened; not a 3 because not every token earns its place.

2 / 3

Actionability

Provides numerous concrete, copy-paste-ready commands with placeholders — theHarvester invocations, curl calls to VirusTotal/Shodan/HIBP, trufflehog/gitleaks, dig, grep — matching the 'fully executable commands; copy-paste ready' anchor.

3 / 3

Workflow Clarity

Section 8 gives a 9-step OSINT sequence, but it is a flat list with no validation checkpoints or verify-then-proceed feedback loops; per guidelines, missing validation in batch/fragile workflows caps workflow clarity at 2.

2 / 3

Progressive Disclosure

The skill is a single monolithic SKILL.md (~225 lines) with no bundle files; while the 10 numbered sections provide reasonable organization, content that could be split (API reference, dork catalog, output spec) is inline, matching the 'some structure but content that should be separate is inline' anchor.

2 / 3

Total

9

/

12

Passed

Description

67%Weight 40%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific and occupies a clear niche, but it lacks an explicit 'Use when...' trigger clause and is missing several natural keyword variations a user might actually say. Adding explicit when-to-use guidance and broader trigger terms would raise it.

Suggestions

Add an explicit 'Use when...' clause listing natural triggers (e.g., 'Use when performing OSINT, recon, email harvesting, breach checks, or GitHub secret scanning').

Include natural user-facing keyword variations such as 'OSINT', 'reconnaissance', 'theHarvester', and 'Google dorking' alongside the technical terms.

DimensionReasoningScore

Specificity

The description enumerates multiple concrete actions — 'email harvesting, social media profiling, breach data checking, employee enumeration, GitHub secret scanning, organizational mapping' — matching the 'lists multiple specific concrete actions' anchor.

3 / 3

Completeness

The 'what' is clearly stated, but there is no 'Use when...' clause or equivalent explicit trigger guidance in the description; per guidelines a missing explicit-when clause caps completeness at 2.

2 / 3

Trigger Term Quality

It includes relevant domain keywords ('email harvesting', 'breach data', 'GitHub secret scanning') but omits natural variations a user would say such as 'OSINT', 'recon', 'theHarvester', or 'Google dorking'; not a 3 because coverage of common terms is incomplete.

2 / 3

Distinctiveness Conflict Risk

OSINT/reconnaissance is a clear, well-defined niche with distinct trigger terms unlikely to conflict with other skills.

3 / 3

Total

10

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.