ctf-osint — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited ctf-osint (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Quick reference for OSINT CTF challenges. Each technique has a one-liner here; see supporting files for full details.
Dispatch on the kind of clue in the prompt/image, not on the story.
| Signal | Technique → file |
|---|---|
| Only a username / handle given | Username OSINT (namechk, whatsmyname, Osint Industries) → social-media.md |
| Twitter/X profile URL, numeric user ID, or snowflake-looking timestamp | Snowflake decode + Nitter + memory.lol → social-media.md |
| Tumblr blog name, Mastodon/BlueSky handle | Platform-specific JSON/API lookups → social-media.md |
| Unicode-rich post text (Cyrillic or mathematical letters in ASCII-looking words) | Homoglyph steganography → social-media.md |
| Image with distinct building, sign, mountain, or road layout | Reverse image + Google Lens / Baidu → geolocation-and-media.md |
| Railroad/road sign text, mileage markers, regional infrastructure | Geolocation via infrastructure maps + MGRS → geolocation-and-media.md |
WxYyyy style or three-random-words string | Google Plus Codes / What3Words → geolocation-and-media.md |
| EXIF present with GPS / camera serial | ExifTool + metadata chain → geolocation-and-media.md |
| Target is a domain / host IP | WHOIS + reverse DNS + ASN → web-and-dns.md |
Tor .onion address or relay fingerprint | Tor relay lookups + Wayback of hidden services → web-and-dns.md |
| GitHub org/user URL, or leaked GitHub token | GitHub repo analysis + commit mining → web-and-dns.md |
| FEC / SEC / public-record style clue (US political or financial) | FEC research → web-and-dns.md |
| Cryptocurrency address + transaction context | On-chain tx tracing → (see ctf-forensics/disk-and-memory.md cross-ref) |
| Strava / fitness route image | Route OSINT via Strava heatmap → social-media.md |
Recognize the kind of artefact; don't chase the story's names.
For inline snippets and quick-reference tables, see quickref.md. The Pattern Recognition Index above is the dispatch table — always consult it first.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.