From osint
Discover an organization's public exposures — leaked credentials and secrets, exposed services and storage, source-code/config leaks, and breach data — from public sources. Use to find what's already exposed about a target (offense) or to reduce your own exposure (defense). Authorized scope.
How this skill is triggered — by the user, by Claude, or both
Slash command
/osint:exposure-discoveryThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
A prioritized list of real public exposures that an attacker could use immediately,
A prioritized list of real public exposures that an attacker could use immediately, with the action to remediate or exploit (within scope) each.
An exposure list: exposure · type · source · validity/confidence · impact · action
(rotate/revoke/remove/harden). Confirmed exposures → security-reporting:finding
(live credentials and exposed data = high+). Defensively, feed an ASM remediation plan.
Validate before acting — many "leaks" are stale or recycled. Treat found credentials as rotate/revoke items; do not authenticate with them unless the engagement explicitly authorizes it. Secrets in git history and public buckets are the most common high-impact exposures.
Provides CDSS development patterns for drug interaction checking, dose validation, clinical scoring (NEWS2, qSOFA), and alert classification integrated into EMR workflows.
npx claudepluginhub jassics/awesome-claude-security --plugin osint