CtrlK
BlogDocsLog inGet started
Tessl Logo

osint-autopilot

End-to-end external OSINT engagement autopilot. Run the FULL osint-methodology pipeline to completion in ONE go for an authorized domain — engagement folder, Stages 1-5 (seed, expansion, enrichment, exposure, convergence), multi-agent per-host content+JS fan-out, headline verification, auto-generated findings, and a consolidated multi-tab .xlsx deliverable. Stops ONLY for Stage 6 (active exploitation) arming and out-of-scope sibling assets. Use whenever asked to "run OSINT / recon / attack-surface" on a target — do NOT deliver a thin passive first pass.

70

Quality

86%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

81%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A tight, actionable runbook with a clear sequenced workflow and explicit verification checkpoints, backed by real bundle scripts. Could be marginally improved by converting script references to markdown links and tightening the opening rationale prose.

Suggestions

Convert $S/<file> script references into markdown links (e.g. [recon_pipeline.sh](scripts/recon_pipeline.sh)) for clearer one-click navigation and stronger progressive-disclosure signaling.

Tighten the opening 'Purpose' sentence and the M1/nmap host-notes into a brief 'Environment notes' aside so the run sequence leads the body.

Spell out how to resolve the ffuf <gopath>/bin/ffuf placeholder (e.g. 'run $(go env GOPATH)/bin/ffuf') so the Workflow invocation is fully copy-paste ready.

DimensionReasoningScore

Conciseness

The body is a lean runbook of commands and gates with almost no concept explanation Claude already knows; a small amount of rationale prose ('Purpose: eliminate the thin first pass failure') and environmental notes could be trimmed, but most tokens earn their place.

4 / 5

Actionability

Provides concrete, mostly copy-paste-ready commands (bash $S/recon_pipeline.sh <domain>, python3 $S/findings_gen.py <domain>, the Workflow call); minor gaps remain in resolving placeholders like <gopath>/bin/ffuf and absolute bucket paths.

4 / 5

Workflow Clarity

A clearly numbered 1–5 run sequence with explicit validation/feedback checkpoints ('Verify headlines yourself — Re-curl every CONFIRMED-worthy claim... Downgrade anything you can't reproduce') and a re-run loop after hand-editing findings.csv, satisfying the batch-operation validation requirement.

5 / 5

Progressive Disclosure

Well-organized sections and the SKILL.md acts as an overview pointing to real one-level-deep bundle scripts (recon_pipeline.sh, host_enum.workflow.js, findings_gen.py, build_xlsx.py, wordlist.txt, requirements.txt all exist); references use $S/path notation rather than markdown links, a minor organization gap.

4 / 5

Total

17

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description that clearly states what the skill does and when to invoke it, with concrete pipeline actions and natural trigger phrases. Minor room to add a few more synonyms (reconnaissance, passive recon) for fully comprehensive keyword coverage.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'engagement folder, Stages 1-5 (seed, expansion, enrichment, exposure, convergence), multi-agent per-host content+JS fan-out, headline verification, auto-generated findings, and a consolidated multi-tab .xlsx deliverable' — with comprehensive coverage of the pipeline.

5 / 5

Completeness

Explicitly answers both what (the full pipeline stages, fan-out, findings, .xlsx deliverable) and when ('Use whenever asked to "run OSINT / recon / attack-surface" on a target'), with a concrete trigger clause present.

5 / 5

Trigger Term Quality

Includes natural terms users would say ('run OSINT / recon / attack-surface') plus a rich triggers list (run recon, full external recon, end to end recon, recon to completion); a few common synonyms like 'reconnaissance' or 'passive recon' are absent, keeping it just below comprehensive.

4 / 5

Distinctiveness Conflict Risk

Occupies a clear niche (end-to-end OSINT autopilot that runs to completion vs. a thin first pass) with distinct triggers; the only adjacency is the companion osint-methodology skill, which this skill explicitly differentiates from as the executable runbook.

5 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
elementalsouls/Claude-OSINT
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.