~ / rigs / elementalsouls / Claude-OSINT

elementalsouls/Claude-OSINT

8 Claude skills · 100+ recon capabilities · 80 secret-regex patterns · 80+ dorks · 9 read-only credential validators · 27 attack-path templates · ~10,000 lines of structured tradecraft. Drop-in SKILL.md files that turn Claude into a god-mod

↗ GitHub ★ 2,772 mit updated 1mo ago project Claude Code
share on X
ARCHETYPE
Skill Collector
Ten-plus skills loaded on demand. A procedural-knowledge library.
CONTEXT TAX · EVERY TURN
~872 tokens
Featherweight · median rig: 2.3k · breakdown
GUARDRAILS
0/5
No committed guardrails · details

Copy this rig

# review before running: this installs third-party code
$ npx degit elementalsouls/Claude-OSINT/.claude ./rig-claude-osint  # inspect, then merge into .claude/

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ npx degit elementalsouls/Claude-OSINT/.claude/skills/run-claude-osint .claude/skills/run-claude-osint
$ npx degit elementalsouls/Claude-OSINT/skills/cloud-saas-exposure .claude/skills/cloud-saas-exposure
$ npx degit elementalsouls/Claude-OSINT/skills/continuous-exposure-monitoring .claude/skills/continuous-exposure-monitoring
$ npx degit elementalsouls/Claude-OSINT/skills/email-domain-security .claude/skills/email-domain-security
$ npx degit elementalsouls/Claude-OSINT/skills/exposure-risk-quantification .claude/skills/exposure-risk-quantification
$ npx degit elementalsouls/Claude-OSINT/skills/identity-provider-recon .claude/skills/identity-provider-recon
$ npx degit elementalsouls/Claude-OSINT/skills/offensive-osint .claude/skills/offensive-osint
$ npx degit elementalsouls/Claude-OSINT/skills/org-attack-surface .claude/skills/org-attack-surface
$ npx degit elementalsouls/Claude-OSINT/skills/osint-autopilot .claude/skills/osint-autopilot
$ npx degit elementalsouls/Claude-OSINT/skills/osint-methodology .claude/skills/osint-methodology

This rig commits no guardrails. Here is the community baseline instead — the deny/ask rules most often found across all 7,204 rigs:

{
  "permissions": {
    "deny": [
      "Read(./.env)",
      "Read(**/.env)",
      "Read(~/.ssh/**)",
      "Bash(rm -rf *)",
      "Read(**/*.pem)",
      "Bash(rm -rf /)",
      "Bash(git push --force:*)",
      "Bash(sudo *)",
      "Read(.env)",
      "Bash(rm -rf /*)",
      "Read(./.env.*)",
      "Read(~/.aws/**)",
      "Bash(git push --force*)",
      "Bash(rm -rf:*)",
      "Read(**/*.key)",
      "Read(**/.env.*)",
      "Bash(sudo:*)",
      "Bash(git reset --hard*)",
      "Bash(git reset --hard:*)",
      "Read(.env.*)"
    ],
    "ask": [
      "Bash(git push:*)",
      "Bash(git push *)",
      "Bash(git commit:*)",
      "Bash(rm *)",
      "Bash(rm:*)",
      "Bash(git rebase *)",
      "Bash(wget *)",
      "Bash(npm publish:*)",
      "Bash(git commit *)",
      "Bash(gh pr merge *)"
    ]
  }
}

Skills (10)

Similar rigs

copied ✓