Works with the AI tools you already use

    CClaude CodeCCursorCCodex CLIGGitHub CopilotGGemini CLIVVS CodeWWindsurf+15 more

    OSINT Investigation Engine — tiered sourcing & certainty-labeled intelligence briefs

    by Julian GM

    1

    For anyone who has to answer for their findings, "the AI said so" is not a source.

    Secure checkout via Stripe

    0 installsSecurity scanned

    See it in action

    You say

    Run an OSINT investigation on Meridian Capital Partners GmbH (Frankfurt) before we onboard them as a payment recipient. Lawful purpose: B2B counterparty due diligence ahead of a supply contract. Tell me whether they're a sound, honestly-run counterparty, with your sources and certainty for each finding.

    Your agent does

    ASSESSMENT — Meridian Capital Partners GmbH (legal person) Purpose: B2B counterparty due diligence · Seed validated: HRB 88421, active.

    Prong: sound, honestly-run counterparty? Verdict: ADVERSE · Evidential confidence: HIGH Reason: a final, unappealed regulatory cease-and-desist for unauthorized deposit-taking (T1-independent, verified) fires the adverse cap; favourable self-reported material cannot lift it.

    FINDINGS (claim · tier · certainty · source · date)

    • Registered GmbH, active — T1-independent · verified · Handelsregister · 2026-06-30
    • Final cease-and-desist, unauthorized deposit-taking — T1-independent · verified · regulator register · 2025-09-12
    • "Record revenue, strongest year" (unaudited) — T1-self · reported · company site · 2026-01
    • "Trusted by two major banks" + award badge — T1-self (borrowed credibility) · reported · company site
    • No insolvency proceeding — T1-independent · verified (verified-absence) · insolvency register · 2026-07

    CORROBORATION & CONFLICTS: the adverse finding is standalone T1-independent and needs no corroboration; self-reported claims carry no countervailing weight. WHAT WOULD CHANGE THE VERDICT: an independently verified regulatory cure would soften ADVERSE to CAUTION at most — never CLEAR on the subject's own say-so.

    What you get

    Perform due diligence on corporate entities using T1-independent sources.Audit claims by verifying them against official regulatory registries.Detect coordinated influence operations and inauthentic digital behavior.Generate defensible intelligence briefs with a mechanical two-axis verdict.

    About this skill

    The problem

    Open-source investigation done by prompt manufactures confidence: the model blends a registry filing, a dated news story, and an undated broker page into one smooth paragraph — and you can no longer tell which claim you can stand behind. For anyone who has to answer for their findings, "the AI said so" is not a source.

    What it does

    This is a structured method the AI follows — not a data service with its own feeds, and not a substitute for regulated screening. It disciplines an open-source investigation end to end:

    • Frames one answerable question (splitting a compound ask into separate prongs, each with its own verdict) and validates the seed identifier before relying on it.
    • Sweeps every relevant modality — selected by subject type, with "not run" logged as a decision — breadth first, blind to each other: corporate & registry, claim/capability coherence, domain & infrastructure, network & beneficial ownership, temporal & media, and (for suspected influence operations) coordination & inauthenticity.
    • Tiers every datum by provenance — T1-independent (registry, regulator, court) kept distinct from T1-self (the subject's own filings, PR, or unaudited numbers), down to T4 (undated/anonymous — a lead, not a fact).
    • Labels every finding verified / reported / inferred / unknown, with verified earned only by a T1-independent source or ≥2 independent, dated, concordant sources — a self-interested claim never reaches verified on its own say-so.
    • Surfaces conflicts instead of smoothing them, and closes with a mechanical two-axis call from a fixed table — an evidential-confidence level (HIGH / MODERATE / LOW / INSUFFICIENT) paired with a CLEAR / CAUTION / ADVERSE / INSUFFICIENT verdict — so a confidently-caught fraud reads as "ADVERSE, high confidence," and a genuinely clean subject earns an honest CLEAR.
    • Delivers an intelligence brief with a findings table, corroboration notes, open leads, and a full audit trail a second analyst could retrace.

    Honest by design

    A check it could not run is marked unknown — never quietly passed off as "nothing found"; but a register it did check and found clean supports a genuine CLEAR, so it is not a fraud-hammer either. When sources disagree it marks the point disputed and downgrades certainty. It never invents a registry number, filing, date, or URL. A withheld or blocked verification is treated as a finding in itself. That discipline is the difference between an investigation that was done and one that only looked done.

    Method + technique, not a checklist

    Beyond the framework, each modality ships a technique playbook with its false-positive trap (name collisions, privacy-proxy WHOIS read as "unknown" not "suspicious," guilt-by-proximity, nominee-vs-UBO, borrowed credibility, forged EXIF). It reasons like a trained analyst — separating what an independent source confirms from what only the subject claims, and separating coordination (lawful by default) from inauthenticity.

    Built for hard cases

    It carries multi-granularity attribution (behaviour / origin / specific entity, each with its own certainty), answers point-in-time questions ("what was knowable as of date D"), and handles reporting whose evidence is non-public: it will cite a bona-fide public-interest investigation but never launder leaked or hacked data, and never reaches verified on that basis alone.

    Lawful by design

    A mandatory legal/ethics gate runs first and is non-negotiable: public sources only, data minimization, a legitimate-purpose allowlist with a falsifiability test for investigating a person, GDPR-aware handling of natural vs legal persons, a protected-subject rule (activists, journalists, whistleblowers), 1:1-only facial verification with no de-anonymization, and an explicit refusal of doxxing, stalking, intimate-partner monitoring, or disguised surveillance. This is investigative OSINT with provenance — not a surveillance tool.

    Signed & tamper-evident

    The assessment logic — the legal/ethics gate, the tiering and certainty rules, the two-axis verdict table — ships under a detached GPG signature over a SHA-256 manifest, with verification instructions included. Cross-check the signing-key fingerprint against this listing (an independent channel):

    3E5C 01D0 6619 A997 5C83 DDA7 7273 DD27 D9C1 E2B1

    Alter a single rule and verification fails. You are running logic you can prove hasn't been tampered with. (This is tamper-evidence — a cryptographic integrity guarantee — not a third-party audit of the methodology.)

    Why this beats prompting it yourself

    A one-off prompt gives you a fluent paragraph with no chain of custody. This ties every conclusion to a tiered source and a certainty label, enforces corroboration before "verified," and ends in a verdict you can defend to an editor, a compliance officer, or a board. The output is auditable, not improvised.

    Part of the suite

    This is the horizontal engine. For deep single-company vetting use company due diligence; for a vendor invoice or bank-detail change use Payment Fraud Triage. Run the Engine for the general investigation and feed either.

    Need this running inside your organisation?

    This skill is the method. If you want it integrated into your actual workflow — wired to your data sources, your case format, your compliance requirements, with the verdict logic adapted and maintained for your team — that is an implementation engagement. Contact: julianescorpio@proton.me (reference: OSINT Engine).

    Known limitations

    Public-source data only — no paywalled or private access, no login/paywall bypass. It is a reasoning/method layer: it directs the collection your agent's own web/search/MCP tools perform and ships no data connectors of its own. Coverage depends on the sources reachable in your setup, and beneficial-ownership access varies by jurisdiction. It outputs a narrative brief, not machine-readable IOC/TLP feeds. It is

    How to install

    Drop the file into your AI Agent. Works with Claude, Cursor, ChatGPT, and 20+ more.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean today

    Listedtoday

    Creator

    Frequently Asked Questions

    Popular in AI Agents & LLM Ops