From osint
Map a target organization's external footprint and attack surface from public sources — domains, subdomains, IP ranges, exposed services, technologies, and organizational details. Use at the start of an engagement (or for attack-surface management) to see what an attacker sees. Authorized scope, public sources.
How this skill is triggered — by the user, by Claude, or both
Slash command
/osint:osint-footprintingThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
A structured, organized map of the target's internet-facing attack surface, built
A structured, organized map of the target's internet-facing attack surface, built from public/passive sources, ready to drive testing or defensive remediation.
reference.md for sources)network-security:network-pentest if/when authorized).security-diagramming:mindmap).An attack-surface inventory: asset · type · service/tech · exposure · source · notes,
plus a prioritized list of where to test (offense) or remediate (defense). Feed
exposures to exposure-discovery and live hosts to network-security.
Footprinting is passive and public-source — it shows the attacker's outside view. Forgotten/legacy and dev/staging assets exposed to the internet are the highest-value finds. Acquisitions and alternate brands quietly expand the surface — enumerate them. Stay within the authorized scope even though sources are public.
Provides CDSS development patterns for drug interaction checking, dose validation, clinical scoring (NEWS2, qSOFA), and alert classification integrated into EMR workflows.
npx claudepluginhub jassics/awesome-claude-security --plugin osint