CtrlK
BlogDocsLog inGet started
Tessl Logo

osint-methodology

Comprehensive OSINT methodology for external red-team operations and authorized attack-surface assessments. Covers the 5-stage recon pipeline, asset-graph discipline, severity rubric, confidence upgrade workflows, time budgeting, identity-fabric mapping, breach×identity correlation, detectability tagging, detection-aware probing, WAF/CDN bypass, vulnerability prioritization, phishing infrastructure planning, bug bounty submission, and client deliverable templates. Use when planning or executing reconnaissance against authorized targets, mapping an organization's external attack surface, investigating a person/entity, or producing client deliverables.

62

Quality

73%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/osint-methodology/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

62%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

This is a well-structured, comprehensive OSINT methodology framework that excels at workflow clarity and systematic organization of a complex multi-stage process. Its main weakness is that it operates as a high-level playbook that defers all concrete implementation details to a companion skill that isn't included in the bundle, reducing actionability. The content is reasonably concise for its ambitious scope but could be tightened in places where it explains concepts Claude would already know.

Suggestions

Include the referenced 'offensive-osint' companion skill in the bundle, or inline the most critical concrete implementations (e.g., key curl commands, top 5 dork patterns, bucket permutation wordlist) to make the skill independently actionable.

Split specialty domains (§13), client deliverable templates (§16), and bug bounty guidance (§15) into separate referenced files to reduce the monolithic nature of the main SKILL.md.

Add at least one end-to-end worked example showing a complete finding from seed discovery through to the output schema, demonstrating the pipeline with concrete tool commands rather than just tool names.

Trim the anti-patterns section (§14) to only items that are non-obvious — entries like 'Attribution by IP geolocation. VPNs and residential proxies exist.' explain things Claude already knows.

DimensionReasoningScore

Conciseness

The skill is extensive (~480 lines) and covers a lot of ground efficiently for its scope, but includes some content Claude already knows (e.g., explaining what UTC is, basic concepts like 'VPNs and residential proxies exist'). The anti-patterns section and some table entries could be tighter. However, most content is domain-specific methodology that genuinely adds value.

2 / 3

Actionability

The skill provides structured frameworks, severity rubrics, confidence upgrade workflows, and clear decision trees, which are highly actionable at a methodological level. However, it deliberately defers all concrete implementation (curl commands, regexes, wordlists, probe paths) to a companion skill 'offensive-osint' that is not included in the bundle. The skill tells you *what* to do but not *how* — no executable code, no copy-paste commands, no concrete tool invocations beyond tool names.

2 / 3

Workflow Clarity

The 5-stage pipeline is clearly sequenced with explicit ordering, time budgets, abort conditions, and priority rankings. The detection-aware probing section (§6.4) provides an excellent back-off ladder with explicit escalation/de-escalation steps. Confidence upgrade workflows provide clear validation checkpoints for each asset type. The engagement profiles provide clear decision points for scope and depth.

3 / 3

Progressive Disclosure

The skill makes extensive references to a companion skill 'offensive-osint' with specific section numbers (§13, §16.1, §16.8, §16.14, §16.15, §20, §21, §22, §23, §29.2), which is good progressive disclosure design. However, no bundle files are provided, meaning none of these references are actually resolvable. The SKILL.md itself is a monolithic document with 18 sections that could benefit from splitting some content (e.g., specialty OSINT domains, client deliverable templates) into separate files.

2 / 3

Total

9

/

12

Passed

Description

85%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

This is a strong skill description that excels in specificity, completeness, and distinctiveness. It clearly defines what the skill does with numerous concrete actions and includes an explicit 'Use when...' clause with multiple trigger scenarios. The main weakness is that some terminology is overly specialized jargon that users may not naturally use, though core terms like 'OSINT', 'reconnaissance', and 'attack surface' are present.

Suggestions

Add more natural-language trigger terms that users would commonly say, such as 'subdomain enumeration', 'open source intelligence', 'target profiling', 'external pentest', or 'information gathering' to improve discoverability.

DimensionReasoningScore

Specificity

The description lists numerous specific concrete actions: 5-stage recon pipeline, asset-graph discipline, severity rubric, confidence upgrade workflows, identity-fabric mapping, breach×identity correlation, detectability tagging, WAF/CDN bypass, vulnerability prioritization, phishing infrastructure planning, bug bounty submission, and client deliverable templates. This is highly specific and comprehensive.

3 / 3

Completeness

The description clearly answers both 'what' (comprehensive OSINT methodology covering specific stages and techniques) and 'when' with an explicit 'Use when...' clause covering four distinct trigger scenarios: planning/executing reconnaissance, mapping attack surfaces, investigating persons/entities, and producing client deliverables.

3 / 3

Trigger Term Quality

While it includes some natural terms like 'reconnaissance', 'attack surface', 'red-team', 'bug bounty', and 'phishing', many terms are specialized jargon (e.g., 'asset-graph discipline', 'confidence upgrade workflows', 'identity-fabric mapping', 'breach×identity correlation') that users are unlikely to naturally say. It's missing simpler trigger terms like 'OSINT', 'recon', 'enumeration', 'subdomain discovery', 'open source intelligence'—though 'OSINT' does appear in the first sentence.

2 / 3

Distinctiveness Conflict Risk

The description carves out a very clear niche in external red-team OSINT and reconnaissance. The combination of specific techniques (WAF/CDN bypass, breach correlation, phishing infrastructure planning) and the explicit authorization context makes it highly unlikely to conflict with other skills.

3 / 3

Total

11

/

12

Passed

Validation

90%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation10 / 11 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

10

/

11

Passed

Repository
elementalsouls/Claude-OSINT
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.