Works with the AI tools you already use
external reconnaissance osint assessment
Authorized OSINT assessment and attack surface mapping for defensive security and governance review.
$18
external reconnaissance osint assessment
Example session with this skill installed
Perform a passive OSINT assessment for acme-corp.com based on the provided Shodan JSON export. Focus on exposed cloud storage and email security records for a defensive review.
- Read your context and instructions
- Compiled the external reconnaissance osint
- Generated the document
I have analyzed the provided Shodan export for acme-corp.com. The assessment identified 12 unique assets with 3 high-priority exposures related to misconfigured S3 buckets and missing DMARC records.
External Reconnaissance & Exposure Register
| Finding Title | Affected Asset | Exposure Type | Confidence | Risk Rationale | Recommended Action |
|---|---|---|---|---|---|
| Unprotected S3 Bucket | acme-backup-prod.s3.amazonaws.com | Cloud Storage | Confirmed | Publicly listable directory containing database backups. | Restrict bucket access via IAM policy. |
| Missing DMARC Policy | acme-corp.com (DNS) | Email Security | Confirmed | Increases risk of domain spoofing and phishing campaigns. | Implement DMARC 'reject' or 'quarantine' policy. |
| Exposed Dev Dashboard | dev.acme-corp.com (Port 8080) | Shadow IT | Likely | Unauthenticated dashboard revealing internal environment variables. | Implement SSO or IP-based access control. |
| Expired TLS Certificate | legacy-api.acme-corp.com | Infrastructure | Confirmed | Potential for MitM attacks on legacy traffic. | Renew certificate or decommission the endpoint. |
Next steps
- Immediate Containment: Restrict public access to the identified S3 bucket and dev dashboard.
- Policy Update: Deploy a DMARC record to the primary domain's DNS.
- Internal Audit: Verify if the legacy API endpoint is still required by active business processes.
external-reconnaissance-osint-assessment.pdf
PDF · document
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
The problem
Mapping a digital footprint manually is slow and prone to overlooking exposed assets. Security teams often struggle to convert raw OSINT data into actionable risk registers that meet governance and defensive standards.
What it does
- Generates structured external reconnaissance reports based on authorized domain or brand scopes.
- Logs source provenance for DNS records, certificates, public repositories, and cloud storage findings.
- Categorizes exposures by confidence levels and maps them to risk rationales.
- Produces remediation plans for leaked secrets, weak email security, and unmanaged internet-facing assets.
- Sanitizes output by identifying sensitive exposure indicators without disclosing raw credentials or PII.
Frameworks & tools
Supports data exports from Shodan, Censys, SecurityTrails, VirusTotal, and GitHub. Includes Python helpers for exposure registration and Shodan API enrichment.
Why this beats prompting it yourself
Writing prompts for OSINT often results in "hallucinated" vulnerabilities or dangerous exploit suggestions. This skill enforces strict defensive boundaries, ensuring reports remain focused on governance and remediation rather than unauthorized offensive tactics.
Use cases
- Pre-penetration testing reconnaissance to define and validate assessment scope.
- M&A due diligence to identify the digital liabilities of a target organization.
- Continuous attack surface monitoring for leaked secrets and exposed cloud buckets.
- Supplier security assessments to verify the external posture of third-party partners.
Known limitations
Does not perform active scanning or brute forcing. Requires manual input of tool exports or API keys for automated collection scripts.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 1 month ago
- Passed all security checks, Safe to install
Needs access to