Works with the AI tools you already use
OSINT Investigation Engine — tiered sourcing & certainty-labeled intelligence briefs
by Julian GM
For anyone who has to answer for their findings, "the AI said so" is not a source.
Secure checkout via Stripe
See it in action
You say
Run an OSINT investigation on Meridian Capital Partners GmbH (Frankfurt) before we onboard them as a payment recipient. Lawful purpose: B2B counterparty due diligence ahead of a supply contract. Tell me whether they're a sound, honestly-run counterparty, with your sources and certainty for each finding.
Your agent does
ASSESSMENT — Meridian Capital Partners GmbH (legal person) Purpose: B2B counterparty due diligence · Seed validated: HRB 88421, active.
Prong: sound, honestly-run counterparty? Verdict: ADVERSE · Evidential confidence: HIGH Reason: a final, unappealed regulatory cease-and-desist for unauthorized deposit-taking (T1-independent, verified) fires the adverse cap; favourable self-reported material cannot lift it.
FINDINGS (claim · tier · certainty · source · date)
- Registered GmbH, active — T1-independent · verified · Handelsregister · 2026-06-30
- Final cease-and-desist, unauthorized deposit-taking — T1-independent · verified · regulator register · 2025-09-12
- "Record revenue, strongest year" (unaudited) — T1-self · reported · company site · 2026-01
- "Trusted by two major banks" + award badge — T1-self (borrowed credibility) · reported · company site
- No insolvency proceeding — T1-independent · verified (verified-absence) · insolvency register · 2026-07
CORROBORATION & CONFLICTS: the adverse finding is standalone T1-independent and needs no corroboration; self-reported claims carry no countervailing weight. WHAT WOULD CHANGE THE VERDICT: an independently verified regulatory cure would soften ADVERSE to CAUTION at most — never CLEAR on the subject's own say-so.
What you get
About this skill
The problem
Open-source investigation done by prompt manufactures confidence: the model blends a registry filing, a dated news story, and an undated broker page into one smooth paragraph — and you can no longer tell which claim you can stand behind. For anyone who has to answer for their findings, "the AI said so" is not a source.
What it does
This is a structured method the AI follows — not a data service with its own feeds, and not a substitute for regulated screening. It disciplines an open-source investigation end to end:
- Frames one answerable question (splitting a compound ask into separate prongs, each with its own verdict) and validates the seed identifier before relying on it.
- Sweeps every relevant modality — selected by subject type, with "not run" logged as a decision — breadth first, blind to each other: corporate & registry, claim/capability coherence, domain & infrastructure, network & beneficial ownership, temporal & media, and (for suspected influence operations) coordination & inauthenticity.
- Tiers every datum by provenance — T1-independent (registry, regulator, court) kept distinct from T1-self (the subject's own filings, PR, or unaudited numbers), down to T4 (undated/anonymous — a lead, not a fact).
- Labels every finding verified / reported / inferred / unknown, with verified earned only by a T1-independent source or ≥2 independent, dated, concordant sources — a self-interested claim never reaches verified on its own say-so.
- Surfaces conflicts instead of smoothing them, and closes with a mechanical two-axis call from a fixed table — an evidential-confidence level (HIGH / MODERATE / LOW / INSUFFICIENT) paired with a CLEAR / CAUTION / ADVERSE / INSUFFICIENT verdict — so a confidently-caught fraud reads as "ADVERSE, high confidence," and a genuinely clean subject earns an honest CLEAR.
- Delivers an intelligence brief with a findings table, corroboration notes, open leads, and a full audit trail a second analyst could retrace.
Honest by design
A check it could not run is marked unknown — never quietly passed off as "nothing found"; but a register it did check and found clean supports a genuine CLEAR, so it is not a fraud-hammer either. When sources disagree it marks the point disputed and downgrades certainty. It never invents a registry number, filing, date, or URL. A withheld or blocked verification is treated as a finding in itself. That discipline is the difference between an investigation that was done and one that only looked done.
Method + technique, not a checklist
Beyond the framework, each modality ships a technique playbook with its false-positive trap (name collisions, privacy-proxy WHOIS read as "unknown" not "suspicious," guilt-by-proximity, nominee-vs-UBO, borrowed credibility, forged EXIF). It reasons like a trained analyst — separating what an independent source confirms from what only the subject claims, and separating coordination (lawful by default) from inauthenticity.
Built for hard cases
It carries multi-granularity attribution (behaviour / origin / specific entity, each with its own certainty), answers point-in-time questions ("what was knowable as of date D"), and handles reporting whose evidence is non-public: it will cite a bona-fide public-interest investigation but never launder leaked or hacked data, and never reaches verified on that basis alone.
Lawful by design
A mandatory legal/ethics gate runs first and is non-negotiable: public sources only, data minimization, a legitimate-purpose allowlist with a falsifiability test for investigating a person, GDPR-aware handling of natural vs legal persons, a protected-subject rule (activists, journalists, whistleblowers), 1:1-only facial verification with no de-anonymization, and an explicit refusal of doxxing, stalking, intimate-partner monitoring, or disguised surveillance. This is investigative OSINT with provenance — not a surveillance tool.
Signed & tamper-evident
The assessment logic — the legal/ethics gate, the tiering and certainty rules, the two-axis verdict table — ships under a detached GPG signature over a SHA-256 manifest, with verification instructions included. Cross-check the signing-key fingerprint against this listing (an independent channel):
3E5C 01D0 6619 A997 5C83 DDA7 7273 DD27 D9C1 E2B1
Alter a single rule and verification fails. You are running logic you can prove hasn't been tampered with. (This is tamper-evidence — a cryptographic integrity guarantee — not a third-party audit of the methodology.)
Why this beats prompting it yourself
A one-off prompt gives you a fluent paragraph with no chain of custody. This ties every conclusion to a tiered source and a certainty label, enforces corroboration before "verified," and ends in a verdict you can defend to an editor, a compliance officer, or a board. The output is auditable, not improvised.
Part of the suite
This is the horizontal engine. For deep single-company vetting use company due diligence; for a vendor invoice or bank-detail change use Payment Fraud Triage. Run the Engine for the general investigation and feed either.
Need this running inside your organisation?
This skill is the method. If you want it integrated into your actual workflow — wired to your data sources, your case format, your compliance requirements, with the verdict logic adapted and maintained for your team — that is an implementation engagement. Contact: julianescorpio@proton.me (reference: OSINT Engine).
Known limitations
Public-source data only — no paywalled or private access, no login/paywall bypass. It is a reasoning/method layer: it directs the collection your agent's own web/search/MCP tools perform and ships no data connectors of its own. Coverage depends on the sources reachable in your setup, and beneficial-ownership access varies by jurisdiction. It outputs a narrative brief, not machine-readable IOC/TLP feeds. It is
How to install
Drop the file into your AI Agent. Works with Claude, Cursor, ChatGPT, and 20+ more.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean today
- 30-day refund guarantee
- One-time purchase, yours forever
- Secure checkout via Stripe
Creator
Frequently Asked Questions
Popular in AI Agents & LLM Ops
designing-hybrid-context-layers
Architects the right retrieval strategy for every query — teaching your agent when to use RAG, a knowledge graph, or a temporal index instead of defaulting to vector search for everything.
truth-first
Eliminate hallucinations with an evidence-first verification framework for system state, configs, and file contents.

prompt-engineer
Professional prompt engineering patterns for building robust, secure, and production-ready LLM applications.
codex-grade-coding
Turn your AI agent into a senior engineer with strict task classification and verification-driven coding protocols.