offensive-osint (Claude-Red)
OSINT methodology skill for red-team recon: domain, email, GitHub leaks, Shodan/Censys, breach data, geoint.
🛡️ AgentReady threat assessment
MAESTRO 7-layer threat model + OWASP AIVSS risk score for offensive-osint (Claude-Red), derived from its capabilities.
These scores are auto-generated from public information (the agent's own listing, docs, and repository) using the canonical OWASP AIVSS formula and the MAESTRO framework — an estimate for guidance, not a penetration test, audit, or certification. See the scoring methodology — every score is re-derived by the same automated method as an agent's public evidence changes.
Overview
A reconnaissance skill from Claude-Red covering domain recon, email harvesting, social-media profiling, GitHub/code-leak discovery, Shodan/Censys enumeration, breach-data lookup, infrastructure mapping, crypto tracing, and geospatial intelligence. Surface: drives outbound recon tooling and API queries to build an attack-surface map.
Key features and capabilities
- Full-spectrum OSINT: domains, people, infra
- Shodan/Censys, breach data, GitHub leaks
- Crypto tracing and geolocation workflows
Use cases
- Map the attack surface of an authorized target
- Investigate a person or organization