What problem does it solve? Turning a single identifier (email, domain, username, phone, company, or IP) into rich machine-readable intelligence usually requires knowing which of hundreds of OSINT sources accept programmatic queries, which need no API key, and what each endpoint actually returns. This Skill provides a verified catalog of those sources so an agent can script enrichment lookups instead of improvising web searches. ## Core Features & Use Cases - Keyless-first source catalog: Hundreds of endpoints tagged by auth level (keyless, free-key, free-tier, paid, shaky) with concrete curl examples and honest ToS/freshness caveats. - Nine category references: Breach exposure, infrastructure recon, developer identity, contact enrichment, public records, presence oracles, phone/messaging, market signals, and Claude connector/MCP alternatives. - Waterfall chaining guidance: Pre-built lookup chains such as company name to canonical domain to subdomains to contributor emails to verified contacts. - Use Case: Given a target company domain, pull subdomains from Cert Spotter, find developer emails via GitHub commits, verify them with Abstract, and enrich the people through Apollo or People Data Labs. ## Quick Start Ask the agent to enrich an email address or enumerate subdomains for a domain using the keyless OSINT sources in this catalog.