useosint

Routes identifiers like emails, domains, and usernames to OSINT investigation workflows.

38|2|Updated Aug 2, 2026
One-click install
npx skills add https://github.com/UseOSINT/Skills --skill useosint-useosint
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: useosint
Source: https://github.com/UseOSINT/Skills/tree/main/skills/useosint
Command: npx skills add https://github.com/UseOSINT/Skills --skill useosint-useosint

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve? Investigators and analysts often receive a single identifier — an email, phone number, domain, or photo — without knowing which open-source intelligence technique applies or where to start. This Skill acts as a router that maps any selector to the correct investigation workflow while enforcing lawful scoping and evidence grading. ## Core Features & Use Cases - Selector-based routing: Maps names, emails, phone numbers, usernames, domains, companies, photos, crypto addresses, and aircraft/vessel identifiers to the matching investigation workflow. - Scope and ethics gating: Requires a documented lawful basis and defined boundaries before any collection begins, with explicit stop conditions for harassment or physical targeting. - Business scenario mapping: Translates requests like vendor vetting, invoice fraud checks, KYB/UBO screening, and attack-surface review into concrete workflow chains. - Evidence grading guidance: Enforces two independent sources per claim, separates identity attribution from claim validity, and records negative findings. - Use Case: A compliance analyst asked to vet a new supplier is routed through company x-ray, ownership tracing, and domain verification workflows, producing a sourced report with confidence levels. ## Quick Start Ask the agent to investigate or verify an identifier such as an email address, domain, or company name and it will set scope and route to the right workflow.

Frequently Asked Questions about useosint

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I start an OSINT investigation from a single email or username?▼

Hand the identifier to the router and it maps it to the matching workflow, such as email analysis for addresses or handle hunting for usernames. It first establishes lawful scope, then chains techniques like breach lookups and WHOIS before grading findings.

What OSINT workflow should I use to vet a supplier or counterparty?▼

Vendor vetting routes through company x-ray, then ownership tracing, then domain verification. This chain covers corporate filings, beneficial ownership, sanctions screening, and infrastructure checks before you sign or pay.

Can this skill verify if a photo or image is authentic?▼

Yes, photo inputs route to authenticity testing, reverse image provenance search, or full geolocation workflows depending on the goal. A shared image match alone is treated as weak evidence and never confirms identity by itself.

Does OSINT investigation require API keys for tools like Shodan or HIBP?▼

Some underlying tools such as Shodan, Have I Been Pwned, and DeHashed require their own API keys. Free alternatives are called out inline within the individual technique workflows.

What are the legal and ethical limits of OSINT investigations?▼

Every workflow requires a documented lawful basis, defined scope, and applicable jurisdiction before collection starts. Requests aimed at confronting, locating, or harassing a private individual in person are explicitly refused.

Why do OSINT reports require two independent sources per claim?▼

Independent means different origin, not different websites, since data brokers often launder the same record. Two-source corroboration plus separate grading of identity attribution prevents name collisions and aggregator echo chambers from becoming false findings.