OSINT Skill
Open Source Intelligence gathering for authorized investigations.
Workflow Routing
| Investigation Type |
Workflow |
Context |
| People lookup |
Workflows/PeopleLookup.md |
PeopleTools.md |
| Company lookup |
Workflows/CompanyLookup.md |
CompanyTools.md |
| Investment due diligence |
Workflows/CompanyDueDiligence.md |
CompanyTools.md |
| Entity/threat intel |
Workflows/EntityLookup.md |
EntityTools.md |
Trigger Patterns
People OSINT:
- "do OSINT on [person]", "research [person]", "background check on [person]"
- "who is [person]", "find info about [person]", "investigate this person"
-> Route to
Workflows/PeopleLookup.md
Company OSINT:
- "do OSINT on [company]", "research [company]", "company intelligence"
- "what can you find about [company]", "investigate [company]"
-> Route to
Workflows/CompanyLookup.md
Investment Due Diligence:
- "due diligence on [company]", "vet [company]", "is [company] legitimate"
- "assess [company]", "should we work with [company]"
-> Route to
Workflows/CompanyDueDiligence.md
Entity/Threat Intel:
- "investigate [domain]", "threat intelligence on [entity]", "is this domain malicious"
- "research this threat actor", "check [domain]", "analyze [entity]"
-> Route to
Workflows/EntityLookup.md
Authorization (REQUIRED)
Before ANY investigation, verify:
STOP if any checkbox is unchecked. See EthicalFramework.md for details.
Resource Index
| File |
Purpose |
EthicalFramework.md |
Authorization, legal, ethical boundaries |
Methodology.md |
Collection methods, verification, reporting |
PeopleTools.md |
People search, social media, public records |
CompanyTools.md |
Business databases, DNS, tech profiling |
EntityTools.md |
Threat intel, scanning, malware analysis, attack targeting patterns |
Integration
Automatic skill invocations:
- Research Skill - Parallel researcher agent deployment (REQUIRED)
- Recon Skill - Technical infrastructure reconnaissance
Agent fleet patterns:
- Quick lookup: 4-6 agents
- Standard investigation: 8-16 agents
- Comprehensive due diligence: 24-32 agents
Researcher types:
| Researcher |
Best For |
| PerplexityResearcher |
Current web data, social media, company updates |
| ClaudeResearcher |
Academic depth, professional backgrounds |
| GeminiResearcher |
Multi-perspective, cross-domain connections |
| GrokResearcher |
Contrarian analysis, fact-checking |
File Organization
Active investigations: write iterative artifacts to a scratch directory under your working area, e.g. scratch/YYYY-MM-DD-HHMMSS_osint-[target]/.
Archived reports: keep finished reports in a dated research folder, e.g. research/YYYY-MM/[target]-osint/.
Ethical Guardrails
ALLOWED: Public sources only - websites, social media, public records, search engines, archived content
PROHIBITED: Private data, unauthorized access, social engineering, purchasing breached data, ToS violations
See EthicalFramework.md for complete requirements.
Version: 2.0 (Canonical Structure)
Last Updated: December 2024
1---2name: osint3description: Open source intelligence gathering. USE WHEN OSINT, due diligence, background check, research person, company intel, investigate.4---56# OSINT Skill78Open Source Intelligence gathering for authorized investigations.910---111213## Workflow Routing1415| Investigation Type | Workflow | Context |16|-------------------|----------|---------|17| People lookup | `Workflows/PeopleLookup.md` | `PeopleTools.md` |18| Company lookup | `Workflows/CompanyLookup.md` | `CompanyTools.md` |19| Investment due diligence | `Workflows/CompanyDueDiligence.md` | `CompanyTools.md` |20| Entity/threat intel | `Workflows/EntityLookup.md` | `EntityTools.md` |2122---2324## Trigger Patterns2526**People OSINT:**27- "do OSINT on [person]", "research [person]", "background check on [person]"28- "who is [person]", "find info about [person]", "investigate this person"29-> Route to `Workflows/PeopleLookup.md`3031**Company OSINT:**32- "do OSINT on [company]", "research [company]", "company intelligence"33- "what can you find about [company]", "investigate [company]"34-> Route to `Workflows/CompanyLookup.md`3536**Investment Due Diligence:**37- "due diligence on [company]", "vet [company]", "is [company] legitimate"38- "assess [company]", "should we work with [company]"39-> Route to `Workflows/CompanyDueDiligence.md`4041**Entity/Threat Intel:**42- "investigate [domain]", "threat intelligence on [entity]", "is this domain malicious"43- "research this threat actor", "check [domain]", "analyze [entity]"44-> Route to `Workflows/EntityLookup.md`4546---4748## Authorization (REQUIRED)4950**Before ANY investigation, verify:**51- [ ] Explicit authorization from client52- [ ] Clear scope definition53- [ ] Legal compliance confirmed54- [ ] Documentation in place5556**STOP if any checkbox is unchecked.** See `EthicalFramework.md` for details.5758---5960## Resource Index6162| File | Purpose |63|------|---------|64| `EthicalFramework.md` | Authorization, legal, ethical boundaries |65| `Methodology.md` | Collection methods, verification, reporting |66| `PeopleTools.md` | People search, social media, public records |67| `CompanyTools.md` | Business databases, DNS, tech profiling |68| `EntityTools.md` | Threat intel, scanning, malware analysis, attack targeting patterns |6970---7172## Integration7374**Automatic skill invocations:**75- **Research Skill** - Parallel researcher agent deployment (REQUIRED)76- **Recon Skill** - Technical infrastructure reconnaissance7778**Agent fleet patterns:**79- Quick lookup: 4-6 agents80- Standard investigation: 8-16 agents81- Comprehensive due diligence: 24-32 agents8283**Researcher types:**84| Researcher | Best For |85|------------|----------|86| PerplexityResearcher | Current web data, social media, company updates |87| ClaudeResearcher | Academic depth, professional backgrounds |88| GeminiResearcher | Multi-perspective, cross-domain connections |89| GrokResearcher | Contrarian analysis, fact-checking |9091---9293## File Organization9495**Active investigations:** write iterative artifacts to a scratch directory under your working area, e.g. `scratch/YYYY-MM-DD-HHMMSS_osint-[target]/`.9697**Archived reports:** keep finished reports in a dated research folder, e.g. `research/YYYY-MM/[target]-osint/`.9899---100101## Ethical Guardrails102103**ALLOWED:** Public sources only - websites, social media, public records, search engines, archived content104105**PROHIBITED:** Private data, unauthorized access, social engineering, purchasing breached data, ToS violations106107See `EthicalFramework.md` for complete requirements.108109---110111**Version:** 2.0 (Canonical Structure)112**Last Updated:** December 2024