安全
安全审查、认证、权限和风险检查
Skills 列表

find-anyone
Build a sourced, corroborated profile of a named individual from public records, social platforms, professional networks, court and property filings, licensing boards, patents, papers and obituaries — anchoring the name to a second selector first so you never fuse two people into one dossier. Use when asked to find, identify, background-check or profile a person, verify someone's claimed employment or credentials, or locate a missing or hard-to-reach individual. Applies to counterparty and investor due diligence, fraud and asset investigation, journalism, skip tracing, missing persons, pre-employment integrity checks on fiduciary roles, and self-exposure audits. Reference at useosint.com/skills/find-anyone.
useosint
geolocate-from-pixels
Geolocate and chronolocate a photo or video from visual evidence alone — plate and phone number formats, road markings, utility poles, bollards, signage typefaces, architecture and vegetation for place; shadow direction and length with SunCalc for time and date. Use when asked where or when a picture was taken, to verify a claimed location without GPS or EXIF, or to match a scene against Google Earth, Street View, Yandex Panoramas, Mapillary or KartaView. Applies to GEOINT and conflict monitoring, insurance and claims verification, journalism fact-checking, and evidence review. Reference at useosint.com/skills/geolocate-from-pixels.
useosint
track-planes-and-ships
Track aircraft and vessels from public ADS-B and AIS broadcasts using ADS-B Exchange, Flightradar24, FlightAware, MarineTraffic, VesselFinder and Equasis. Use when following a tail number or flight, looking up an ICAO 24-bit hex code, registration or callsign, tracing a ship by IMO number or MMSI, checking a flag of convenience or port-call history, finding who owns a private jet or vessel, or analysing AIS gaps and dark-fleet behaviour. Applies to sanctions-evasion detection, trade and supply-chain compliance, asset tracing and recovery, and investigative journalism. Reference at useosint.com/skills/track-planes-and-ships.
useosint
graph-the-network
Build an entity-relationship link-analysis graph of an investigation — nodes, typed edges carrying source and confidence, aliases, and temporal validity — to expose shared infrastructure, bridging nodes and the real principal behind a frontman. Covers Maltego, Neo4j and Cypher, Gephi, centrality and community detection, and entity resolution. Use when an investigation has outgrown a list and needs a graph, or when asked how a set of people, companies and domains connect. Applies to fraud-ring and shell-network detection, AML and sanctions-evasion analysis, and complex corporate-structure work. Reference at useosint.com/skills/graph-the-network.
useosint
pattern-of-life-from-socials
Deep-dive a subject's social media presence — profile metadata, follower and mutual network, content analysis, and posting-time pattern of life across Instagram, Facebook, X/Twitter, TikTok, LinkedIn, Reddit, Telegram and Discord. Use when profiling a social account, mapping someone's associates, inferring a subject's timezone or routine from their posts, or archiving a profile before it is deleted. Applies to threat assessment and executive protection, insider-threat investigation, pre-litigation research, and personal exposure audits — with explicit limits on profiling uninvolved third parties. Reference at useosint.com/skills/pattern-of-life-from-socials.
useosint
what-an-email-reveals
Investigate an email address — MX and syntactic validation, Gravatar lookup, corporate email-format inference, breach exposure, and full mail-header analysis covering the Received chain, Message-ID and SPF, DKIM and DMARC results. Use for email OSINT, verifying whether an address exists, finding accounts registered to it, guessing a company's email format, or tracing where a suspicious message actually came from. Applies to business email compromise and invoice-fraud investigation, phishing triage, vendor-payment verification, and pre-engagement research. Reference at useosint.com/skills/what-an-email-reveals.
useosint
find-hidden-subdomains
Enumerate an organisation's subdomains and sibling domains from Certificate Transparency logs and passive DNS, without sending traffic to the target. Covers crt.sh and CT log queries, certificate SAN fields, subfinder and amass, and newly issued TLS certificates. Use when looking for staging, dev, admin or VPN hosts, mapping the full hostname footprint of a domain, or spotting infrastructure a company forgot it had. Applies to attack-surface mapping, vendor and supply-chain security review, brand-infringement discovery, and M&A technical diligence. Reference at useosint.com/skills/find-hidden-subdomains.
useosint
investigate-anything
Start-here router and tradecraft baseline for any investigation into a person, company, domain, image or selector. Sets authorised scope, turns a vague request into an answerable intelligence question, writes a collection plan, picks the right workflow for the starting selector, and applies source grading and competing-hypothesis discipline. Use for "investigate this person or company", "do OSINT on X", "where do I start", or any open-source intelligence, due diligence, background or attribution task. Applies across due diligence, fraud, threat intelligence, journalism and compliance. Reference at useosint.com/skills/investigate-anything.
useosint
who-really-owns-it
Research companies, directors, shareholders and ultimate beneficial ownership in official corporate registries, filings and offshore datasets — OpenCorporates, UK Companies House and the PSC register, SEC EDGAR, US Secretary of State registries, EU business registers, GLEIF LEI records, OpenOwnership, OpenSanctions and the ICIJ Offshore Leaks database. Use when asked who owns or controls a company, to find a person's other directorships, or to unpick a group structure. Applies to KYB and UBO verification, AML and sanctions screening, nominee and shell-company detection, procurement integrity, and M&A diligence. Reference at useosint.com/skills/who-really-owns-it.
useosint
where-was-this-taken
End-to-end workflow to establish where and when a photo or video was captured and whether it is authentic — evidentiary handling, metadata extraction, reverse image search for provenance, visual geolocation, chronolocation from shadows, and manipulation checks, ending in a location finding with a stated confidence radius. Use when asked to verify where an image was taken, confirm or refute a claimed location or date, or authenticate media before relying on it. Applies to insurance claims, litigation evidence, disinformation analysis, and conflict and human-rights documentation. Reference at useosint.com/skills/where-was-this-taken.
useosint
find-leaks-in-the-wild
Find leaked or mentioned selectors circulating in pastes, leak forums, Telegram channels and dump markets, and judge whether a claimed leak is genuine or a recycled combolist. Covers paste aggregators, site: searches over paste hosts, channel indexes and leak-search services. Use when checking whether a name, email, domain or credential is circulating, verifying a breach claim made against your organisation, or setting up ongoing leak monitoring. Applies to incident response and breach triage, threat intelligence, brand and executive protection, and extortion-claim validation. Reference at useosint.com/skills/find-leaks-in-the-wild.
useosint
google-like-a-spy
Craft advanced search-engine queries and Google dorks to surface hidden files, documents and mentions. Covers site:, filetype:, inurl:, intitle:, intext: and before:/after: operators, verbatim search, exposed directory listings, config files, backups and open S3 buckets, and the operator differences between Google, Bing, DuckDuckGo and Yandex. Use when building a Google dork, hunting a leaked document, or searching paste sites and document repositories for a name, email or selector. Applies to data-exposure audits, pre-engagement reconnaissance, competitive and regulatory research, and insider-leak investigation. Reference at useosint.com/skills/google-like-a-spy.
useosint
ace-step
通过 `runcomfy` CLI 在 RunComfy 上使用 ACE Step 生成、修补和扩展音乐。ACE Step 是 StepFun-AI 的开源权重音乐基础模型——基于标签的作曲(流派、情绪、乐器)、支持多语言歌词和段落标记、5 秒到 4 分钟立体声输出、每秒 $0.0002–0.0003(比 ElevenLabs Music 便宜约 27 倍)。四个端点:ACE Step 文本转音频(默认)、ACE Step 1.5 文本转音频(50+ 语言歌词、改进的结构化歌词处理)、ACE Step 音频修补(在现有音轨内重新生成时间范围)、ACE Step 音频扩展(在现有音轨前后扩展)。触发词包括 "ace step"、"ace-step"、"acestep"、"ACE music"、"open music model"、"cheap AI music"、"inpaint audio"、"audio inpaint"、"extend music"、"audio outpaint"、"lengthen track"、"music with tags" 或任何明确要求使用 ACE Step 生成或编辑音乐的请求。
agentspace-so
ai-music
通过 `runcomfy` CLI 在 RunComfy 上生成 AI 音乐——一个智能路由,覆盖音乐模型目录。路由到 ElevenLabs AI 音乐生成(高级 44.1 kHz 立体声人声曲目,5 秒–5 分钟,$0.0083/秒)和 ACE Step / ACE Step 1.5(StepFun-AI 开源权重,标签驱动作曲,多语言歌词,$0.0002–0.0003/秒,约便宜 27 倍),以及 ACE Step 音频修补(在现有曲目内重新生成时间范围)和 ACE Step 音频外扩(在曲目前或后扩展)。根据用户的实际意图选择正确的模型——高级人声片段、廉价背景音乐库、多语言流行歌曲、修复糟糕的副歌、将 30 秒草稿延长为 2 分钟剪辑——并提供每个模型的文档化提示模式以及最小的 `runcomfy run` 调用。触发词包括“生成音乐”、“制作歌曲”、“AI 音乐”、“背景音乐”、“器乐曲目”、“配乐”、“广告歌”、“主题音乐”、“免版税音乐”、“作曲”、“带歌词的音乐”、“扩展音乐”、“修复这首歌”、“修补音乐”,或任何明确的生成或编辑音乐的请求。
agentspace-so
recon-a-domain-passively
End-to-end passive reconnaissance for a domain, website or IP — builds an asset inventory covering registration, DNS, subdomains, infrastructure, tech stack, history and ownership without sending a single packet to the target. Use when asked to research or profile a domain or website, map what an organisation runs, or investigate a suspicious site without alerting its operator. Applies to vendor and third-party risk assessment, attack-surface review, M&A technical diligence, phishing and fraud-site investigation, and pre-engagement scoping. Reference at useosint.com/skills/recon-a-domain-passively.
useosint
secrets-in-file-metadata
Extract and interpret embedded file metadata with exiftool — EXIF GPS coordinates, camera make, model and serial, DateTimeOriginal and CreateDate timestamps, XMP and IPTC fields, and Office and PDF properties such as Author, Company, LastModifiedBy, template paths and revision counts. Use when reading EXIF from a photo, checking who really wrote a document, dating a file, fingerprinting a camera or phone, or investigating provenance in JPEG, HEIC, RAW, MP4, DOCX, XLSX or PDF. Applies to document-provenance disputes, insider-leak attribution, evidence handling, and pre-publication redaction checks. Reference at useosint.com/skills/secrets-in-file-metadata.
useosint
whose-number-is-this
Investigate a phone number — E.164 normalisation with libphonenumber, phoneinfoga scanning, carrier and line-type identification, VoIP and burner detection, messaging-app registration checks, and reverse-lookup and caller-ID sources. Use for phone OSINT and reverse phone lookup, "who owns this number", identifying a burner or VoIP number, or checking whether a number is registered on WhatsApp, Telegram or Signal. Applies to vishing and business email compromise investigation, verifying a counterparty before sending payment, recruitment and marketplace scam checks, and fraud triage. Reference at useosint.com/skills/whose-number-is-this.
useosint
follow-the-crypto
Trace cryptocurrency addresses and transactions on public blockchains using block explorers including Etherscan, Blockchair, mempool.space and Blockscout. Covers common-input clustering, ENS resolution, exchange deposit addresses, mixers, CoinJoin, Tornado-style pools, cross-chain bridges, and OFAC sanctions screening. Use when following a Bitcoin or Ethereum wallet, investigating where a ransom or scam payment went, or checking an address against sanctions listings. Applies to ransomware incident response, AML and sanctions compliance, fraud recovery and asset tracing, and financial-crime investigation. Reference at useosint.com/skills/follow-the-crypto.
useosint
write-the-intel-brief
Turn findings into a defensible intelligence product — BLUF key judgements, standardised estimative probability language, per-claim sourcing with timestamps and archived copies, separated observation, inference and assessment, documented negative findings and gaps, chain of custody and hashing, and redaction of uninvolved parties. Use when writing an intelligence report, due-diligence memo, evidence pack or executive summary, or when asked to write up an investigation so it survives challenge. Applies to regulated compliance reporting, litigation and disclosure, board and investment committee reporting, and law-enforcement referral. Reference at useosint.com/skills/write-the-intel-brief.
useosint
hunt-a-handle
Enumerate a username across hundreds of platforms with sherlock, maigret and WhatsMyName, then correlate and confirm which accounts genuinely belong to the same person. Use for username OSINT and handle enumeration, "find all accounts for this username", cross-platform account correlation, nickname and screen-name pivots, or turning a handle into a real name. Applies to fraud and synthetic-identity investigation, recruitment and marketplace scam checks, trust-and-safety enforcement, insider-threat work, and personal exposure audits. Reference at useosint.com/skills/hunt-a-handle.
useosint
find-anyone
Build a sourced, corroborated profile of a named individual from public records, social platforms, professional networks, court and property filings, licensing boards, patents, papers and obituaries — anchoring the name to a second selector first so you never fuse two people into one dossier. Use when asked to find, identify, background-check or profile a person, verify someone's claimed employment or credentials, or locate a missing or hard-to-reach individual. Applies to counterparty and investor due diligence, fraud and asset investigation, journalism, skip tracing, missing persons, pre-employment integrity checks on fiduciary roles, and self-exposure audits. Reference at useosint.com/skills/find-anyone.
useosint
geolocate-from-pixels
Geolocate and chronolocate a photo or video from visual evidence alone — plate and phone number formats, road markings, utility poles, bollards, signage typefaces, architecture and vegetation for place; shadow direction and length with SunCalc for time and date. Use when asked where or when a picture was taken, to verify a claimed location without GPS or EXIF, or to match a scene against Google Earth, Street View, Yandex Panoramas, Mapillary or KartaView. Applies to GEOINT and conflict monitoring, insurance and claims verification, journalism fact-checking, and evidence review. Reference at useosint.com/skills/geolocate-from-pixels.
useosint
track-planes-and-ships
Track aircraft and vessels from public ADS-B and AIS broadcasts using ADS-B Exchange, Flightradar24, FlightAware, MarineTraffic, VesselFinder and Equasis. Use when following a tail number or flight, looking up an ICAO 24-bit hex code, registration or callsign, tracing a ship by IMO number or MMSI, checking a flag of convenience or port-call history, finding who owns a private jet or vessel, or analysing AIS gaps and dark-fleet behaviour. Applies to sanctions-evasion detection, trade and supply-chain compliance, asset tracing and recovery, and investigative journalism. Reference at useosint.com/skills/track-planes-and-ships.
useosint
graph-the-network
Build an entity-relationship link-analysis graph of an investigation — nodes, typed edges carrying source and confidence, aliases, and temporal validity — to expose shared infrastructure, bridging nodes and the real principal behind a frontman. Covers Maltego, Neo4j and Cypher, Gephi, centrality and community detection, and entity resolution. Use when an investigation has outgrown a list and needs a graph, or when asked how a set of people, companies and domains connect. Applies to fraud-ring and shell-network detection, AML and sanctions-evasion analysis, and complex corporate-structure work. Reference at useosint.com/skills/graph-the-network.
useosint