ohsint-active-recon — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited ohsint-active-recon (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
The only OhSINT pipeline that sends traffic to the target. Every stage touches it.
Before running, obtain and record a structured authorization reason:
If the user has not provided this, STOP and ask. Do not run with a bare "yes" — capture why (e.g. engagement=ACME-2026-Q2, scope=hackerone_acme.txt). This reason is logged to the audit trail and surfaced in the report provenance.
ohsint active-recon --authorization -t <target>--brute only if the user explicitly wants slow/loud DNS brute-force.--top-ports, --nuclei-severity, --crawl-depth as requested; defaults aretop-100 / high,critical / depth 2.
ohsint wiki-ingest results/.../report.jsonohsint-wiki-ingest skill).~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.