CtrlK
BlogDocsLog inGet started
Tessl Logo

offensive-osint

Comprehensive OSINT methodology skill for offensive security, red team intelligence gathering, and bug bounty reconnaissance. Covers domain recon, email harvesting, social media profiling, GitHub/code leaks, Shodan/Censys enumeration, breach data lookup, employee profiling, infrastructure mapping, cryptocurrency tracing, geospatial intelligence, and AI-assisted analysis workflows. Use when performing reconnaissance against a target domain or organization, investigating a person or entity, tracing cryptocurrency flows, geolocating images or events, or building an attack-surface map.

64

Quality

76%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./Skills/recon/offensive-osint/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

61%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-organized, actionable OSINT reference with concrete tools and a sensible workflow, but the catalog is long, lacks validation checkpoints in its workflow, and inlines bulk reference content that could be split into separate files.

Suggestions

Add explicit validation/verification checkpoints to the Workflow (e.g., confirm screenshots/URLs resolve before archiving, verify JSONL logs parse, re-validate hashes) to lift workflow clarity above 3.

Trim or condense the tool catalog to the most representative tools per category, moving the full list into a separate reference file to improve conciseness and progressive disclosure.

Provide a short copy-paste example of the recommended JSONL log line and artifact-archive command so the logging workflow is fully executable rather than descriptive.

DimensionReasoningScore

Conciseness

Entries are terse one-liners (tool — purpose) and avoid explaining concepts Claude already knows, but the ~400-line bulk tool catalog could be tightened since much is reference data Claude largely recognizes.

3 / 5

Actionability

Concrete tool names, URLs, and purposes plus an actionable artifact/logging workflow ("URL + timestamp + screenshot (PNG) + hash (SHA-256)", "JSONL with a run_id and tool versions") give mostly executable guidance, though no copy-paste code is provided.

4 / 5

Workflow Clarity

The 6-step Workflow section sequences the process and includes a logging step, but it lacks explicit validation checkpoints or feedback loops, leaving checkpoints implicit.

3 / 5

Progressive Disclosure

Clear section headers and one-level-deep organization make navigation easy, but the large inline tool catalog (infra, crypto, geospatial, etc.) could arguably be split into separate reference files rather than inlined.

4 / 5

Total

14

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description that clearly states what the skill covers and when to use it, with natural trigger phrases and a distinct offensive-OSINT niche. Minor headroom only in expanding trigger-term synonyms.

DimensionReasoningScore

Specificity

The description enumerates many concrete capability categories ("domain recon, email harvesting, social media profiling... cryptocurrency tracing, geospatial intelligence, and AI-assisted analysis workflows"), giving comprehensive coverage of the skill's actions rather than vague language.

5 / 5

Completeness

Both halves are explicit: a detailed "what" via the capability list and a concrete "when" via the "Use when performing reconnaissance... investigating a person... tracing cryptocurrency... geolocating images... or building an attack-surface map" trigger clause.

5 / 5

Trigger Term Quality

It includes natural phrases a user would say ("reconnaissance against a target domain", "investigating a person or entity", "tracing cryptocurrency flows", "geolocating images or events", "building an attack-surface map") with good synonym coverage, though a few common variants like "doxing" or "footprinting" are absent.

4 / 5

Distinctiveness Conflict Risk

The offensive-security OSINT framing plus the enumerated category set carves a clear niche unlikely to be mistaken for generic research or web-search skills, with only minimal overlap risk.

5 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
SnailSploit/Claude-Red
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.