investigate-without-getting-made

Guides investigator OPSEC across attribution surfaces, personas, and network egress during OSINT collection.

38|2|Updated Aug 2, 2026
One-click install
npx skills add https://github.com/UseOSINT/Skills --skill investigate-without-getting-made-useosint
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: investigate-without-getting-made
Source: https://github.com/UseOSINT/Skills/tree/main/skills/investigate-without-getting-made
Command: npx skills add https://github.com/UseOSINT/Skills --skill investigate-without-getting-made-useosint

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve? Investigators get burned not by clever adversaries but by platforms doing what they advertise: profile-view notifications, contact-graph suggestions, and logged-in sessions that expose a real identity to the subject. This Skill helps you threat-model who might notice your research, control your attribution surface, and keep research identity permanently separated from real identity. ## Core Features & Use Cases - Threat modeling and posture selection: Match OPSEC effort to adversary capability, from casual registry lookups to monitored criminal infrastructure. - Attribution surface control: Manage IP/ASN, browser and TLS fingerprints, locale, timing, and logged-in account leakage, with a per-surface checklist in reference/attribution-surface.md. - Persona tradecraft: Build, age, operate, and retire compartmented research personas using the step-by-step reference/persona-runbook.md, with explicit legal and ToS boundaries. - Use Case: Before viewing a subject's profile on a platform that notifies viewers, run the pre-action check, switch to an aged persona on a clean egress, view the page, and log the exposure as pseudonymous contact. ## Quick Start Ask the agent to threat-model an upcoming investigation of a subject's social media presence and recommend a proportionate OPSEC posture before any collection begins.

Frequently Asked Questions about investigate-without-getting-made

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I avoid tipping off a subject during OSINT research?▼

Threat-model who might notice and what they would see, then match your posture: clean browser and VPN for public sites, aged persona accounts for logged-in platforms. Prefer archives and caches over live visits, and log every exposure event with a grade from clean to attributed.

What is the biggest OPSEC mistake investigators make?▼

The logged-in slip: viewing a target's profile while signed into a real account, which triggers viewer notifications and exposes your name. Other common burns include real phone numbers used for verification, reused passwords, and corporate network ASNs identifying your employer.

Should I use Tor or a VPN for investigation research?▼

A commercial VPN suits ordinary sites but is blocked by some platforms and flagged as datacentre traffic. Tor offers strong anonymity but exit nodes are publicly listed, triggering blocks and account challenges, so it is wrong for persona accounts. Residential proxies look like consumer connections but carry sourcing and ethics concerns.

Are sockpuppet accounts legal for OSINT investigations?▼

Fake accounts violate most platforms' terms of service, which is generally a contract matter rather than a crime, though the boundary varies by jurisdiction. Impersonating a real identifiable person or an official is criminal in many places. Decide with counsel and record the authorization in writing.

How do I build a research persona that does not get banned?▼

Create personas well before they are needed, with coherent name, locale, timezone, and interests, registered from their permanent egress. Age them with irregular, ordinary activity over time, never reuse identifiers across personas, and use them for observation only.

Why does my research setup keep getting CAPTCHA challenges?▼

Challenges come from flagged egress IPs, datacentre ASNs, mid-session IP changes, or fingerprint inconsistencies. Do not switch IPs mid-session to escape, as that confirms the pattern; stop the session and assume a challenged account may be finished.