offensive-osint

Generate probe paths, wordlists, and evidence-scoped findings for authorized asset discovery.

1|Updated Apr 18, 2026
One-click install
npx skills add https://github.com/jellaharshith/SWIFT --skill offensive-osint-jellaharshith
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: offensive-osint
Source: https://github.com/jellaharshith/SWIFT/tree/main/swift/skills/cbh/skills/offensive-osint
Command: npx skills add https://github.com/jellaharshith/SWIFT --skill offensive-osint-jellaharshith

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) and scripts (resource) components.

What problem does it solve?

This skill solves the problem of turning time-consuming external reconnaissance into a structured, probe-ready workflow for authorized red-team and bug-bounty asset discovery.

Core Features & Use Cases

  • Actionable OSINT recon: Provides concrete probe paths, wordlists, and copy-paste curl one-liners for discovery across web, identity, cloud, and SaaS surfaces.
  • Endpoint and surface prioritization: Uses scoring rubrics (e.g., endpoint interest score and mobile ownership confidence) plus severity decision matrices to help operators focus on the highest-yield findings.
  • Secret triage support with validation: Includes a secret-pattern catalog and read-only secret validators (plus a local stdlib helper script) to mirror and verify likely credential leaks.
  • Evidence-first outputs: Establishes consistent finding fields, evidence hygiene, timestamps, hashing guidance, and rules-of-engagement posture to keep workflows auditable.

Quick Start

Use the offensive-osint skill to generate a prioritized external recon plan for target domain reconnaissance and identify likely OSINT and secret-leak opportunities with evidence-ready artifacts and scoring.

Frequently Asked Questions about offensive-osint

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I generate a probe-ready external reconnaissance plan for subdomain and endpoint discovery?▼

External reconnaissance planning translates authorized target domains into concrete probe paths, wordlists, and copy-paste curl one-liners for subdomain and endpoint discovery. You receive a structured, evidence-scoped workflow that prioritizes high-yield findings for asset discovery.

What is the best way to identify exposed secrets and validate credential leaks during an OSINT operation?▼

Secret identification during OSINT uses a secret-pattern catalog with regex coverage to locate likely credential leaks. Read-only secret validators and a local stdlib helper script mirror and verify these exposed credentials without modifying external assets.

How does severity scoring work for vulnerability and takeover reconnaissance findings?▼

Severity scoring for takeover reconnaissance uses scoring rubrics like endpoint interest score and mobile ownership confidence combined with severity decision matrices. This scoring helps operators focus on the highest-yield findings and prioritize asset discovery targets.

How do I enumerate identity-fabric endpoints and SaaS public surfaces for bug bounty targets?▼

Identity-fabric endpoint enumeration and SaaS public-surface hunting map external identities and exposed SaaS applications. This process generates structured probe paths and wordlists to discover unauthorized access points for bug bounty asset discovery.

Can I use this approach to discover swagger, openapi, and graphql endpoints on external targets?▼

Swagger, OpenAPI, and GraphQL discovery on external targets translates reconnaissance questions into specific probe paths and wordlists. This structured approach yields evidence-scoped findings that fit a guided recon and severity scoring pipeline.

What output formats and evidence hygiene conventions are needed for auditable red-team recon?▼

Auditable red-team recon requires consistent finding fields, evidence hygiene standards, timestamps, and hashing guidance. These output conventions maintain rules-of-engagement posture and ensure workflows remain structured and verifiable for external asset discovery.