Agent skill

pentest-recon-osint

Perform passive reconnaissance and leak intelligence collection with no direct contact to target systems.

Stars 163
Forks 31

Install this agent skill to your Project

npx add-skill https://github.com/majiayu000/claude-skill-registry/tree/main/skills/other/other/pentest-recon-osint

SKILL.md

Pentest Recon OSINT

Stage

  • PTES: 2
  • MITRE: TA0043 - Reconnaissance

Objective

Collect subdomains, identities, leak indicators, and passive attack surface telemetry.

Required Workflow

  1. Validate scope before any active action and reject out-of-scope targets.
  2. Run only authorized checks aligned to PTES, OWASP WSTG, NIST SP 800-115, and MITRE ATT&CK.
  3. Write findings in canonical finding_schema format with reproducible PoC notes.
  4. Honor dry-run mode and require explicit --i-have-authorization for live execution.
  5. Export deterministic artifacts for downstream skill consumption.

Execution

bash
python skills/pentest-recon-osint/scripts/recon_osint.py --scope scope.json --target <target> --input <path> --output <path> --format json --dry-run

Outputs

  • subdomains.txt
  • emails.txt
  • technologies.json
  • leaked-creds.json
  • osint-report.json

References

  • references/tools.md
  • skills/autonomous-pentester/shared/scope_schema.json
  • skills/autonomous-pentester/shared/finding_schema.json

Legal and Ethical Notice

text
WARNING AUTHORIZED USE ONLY
This skill executes real security testing tools against live targets.
Use only with written authorization.

Expand your agent's capabilities with these related and highly-rated skills.

Didn't find tool you were looking for?

Be as detailed as possible for better results