CtrlK
BlogDocsLog inGet started
Tessl Logo

osint-methodology

Comprehensive OSINT methodology for external red-team operations and authorized attack-surface assessments. Covers the 6-stage recon pipeline (seed → asset expansion → enrichment → exposure analysis → convergence → operator-armed active validation) with connector-resilience and stage-vs-gating discipline, asset-graph discipline, severity rubric, confidence upgrade workflows, time budgeting, identity-fabric mapping, breach×identity correlation with per-person identity dossiers, detectability tagging, detection-aware probing, WAF/CDN bypass, vulnerability prioritization, phishing infrastructure planning, bug bounty submission, and client deliverable templates. Use when planning or executing reconnaissance against authorized targets, mapping an organization's external attack surface, investigating a person/entity, or producing client deliverables.

65

Quality

80%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/osint-methodology/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

71%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A dense, well-structured methodology body that assumes competence and gives concrete, specific guidance with a clearly sequenced, validation-checked pipeline. Its main weakness is progressive disclosure: it is a large monolith with no local bundle files, inlining reference material that could live in separate files.

Suggestions

Split the inlined reference tables (§8.1 asset taxonomy, §9 severity anchors, §7.2 time budgets, §12 breach sources) into local reference files (e.g. references/severity-rubric.md, references/asset-taxonomy.md) and link them from SKILL.md so the body acts as an overview rather than a 480-line monolith.

De-duplicate the repeated 'do not paste PII/creds into cloud LLMs' and 'single-source attribution' guidance — it appears in §1, §5, and §14 — into a single canonical location to recover tokens.

Add a short table-of-contents block near the top mapping each section to its purpose, so an operator can jump to the relevant stage without scanning the whole file.

DimensionReasoningScore

Conciseness

Dense and information-rich with no basic-concept padding (it assumes Claude's competence and a deliberate trim history is documented), but the ~480-line body carries minor redundancy — the 'no PII/creds into cloud LLMs' and 'single-source attribution' guidance recurs across §1, §5, and §14.

4 / 5

Actionability

Highly concrete guidance for an instruction skill — named tools (crt.sh, HudsonRock Cavalier, HIBP), exact probe paths (`.git/config`, `.env`, `/actuator/env`), a finding schema, severity anchors, and time-budget tables — but most copy-paste-ready commands/regexes are deferred to the companion skill rather than present here.

4 / 5

Workflow Clarity

The 6-stage pipeline is clearly sequenced with explicit abort conditions, confidence-upgrade validation (TENTATIVE→FIRM→CONFIRMED), a §6.4 back-off feedback loop, and Stage-6 scope gating; minor gaps arise because per-stage module steps stay high-level with implementation pushed to the companion skill.

4 / 5

Progressive Disclosure

Well-organized into 18 headed sections with clearly signaled pointers to the companion 'offensive-osint' skill, but as a standalone skill it is a monolithic ~480-line SKILL.md with zero local reference files — reference-style content (asset taxonomy, severity rubric, time budgets, breach-source tables) is inlined rather than split into local files the body points to.

3 / 5

Total

15

/

20

Passed

Description

88%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description that clearly states both what the skill covers and when to use it, with concrete capability enumeration and an explicit trigger clause. It is slightly long and could trim a few of the more specialized sub-capabilities, but reads as comprehensive rather than padded.

DimensionReasoningScore

Specificity

Lists many concrete actions — '6-stage recon pipeline', 'asset-graph discipline', 'severity rubric', 'identity-fabric mapping', 'breach×identity correlation', 'phishing infrastructure planning', 'bug bounty submission', 'client deliverable templates' — giving comprehensive coverage of specific capabilities rather than vague language.

5 / 5

Completeness

Explicitly answers both 'what' (the enumerated capability list) and 'when' via a concrete 'Use when planning or executing reconnaissance against authorized targets, mapping an organization's external attack surface, investigating a person/entity, or producing client deliverables' trigger clause.

5 / 5

Trigger Term Quality

Good natural-term coverage including synonyms ('reconnaissance', 'recon', 'external red-team', 'attack surface', 'OSINT methodology', 'investigating a person/entity'), though a few common variations users might say (e.g. 'footprint', 'ASM') appear only in the triggers field, not the description prose itself.

4 / 5

Distinctiveness Conflict Risk

Mostly distinct niche (authorized external red-team / attack-surface recon) with explicit scoping, but the breadth of triggers creates minor overlap risk with closely related general-OSINT or the referenced companion 'offensive-osint' skill.

4 / 5

Total

18

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

skill_md_line_count

SKILL.md is long (521 lines); consider splitting into references/ and linking

Warning

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

14

/

16

Passed

Repository
elementalsouls/Claude-OSINT
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.