ctf-osint
Investigate Authorized CTF OSINT Challenges
CTF OSINT clues often span disconnected public sources and media artifacts. This skill organizes practical methods for authorized identity, geolocation, archive, DNS, and web research.
Detente y solicita confirmación antes de instalar.
Revisa el plan y obtén el consentimiento explícito del usuario antes de modificar archivos.
Instalar con mi Agente
Copia esta solicitud en tu Agente. Incluye la página canónica del Skill y el manifiesto.
Review the Skillstore skill "ctf-osint" from https://skillstore.io/skills/ljagiello-ctf-osint.md and its manifest at https://skillstore.io/api/skills/ljagiello-ctf-osint/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.Tu Agente debe seguir mostrando su plan y solicitar cualquier confirmación exigida por la política de seguridad.
Recursos legibles por agentes
Usa estos enlaces cuando un agente de IA, crawler o script necesite contexto limpio en vez de leer la página completa.
Pruébalo
Usando "ctf-osint". Identify the string 4V FH 246 677.
Resultado esperado:
Likely format: MGRS coordinate. Confirm the spacing and precision, convert it with a trusted MGRS tool, then verify the resulting location against challenge clues.
Usando "ctf-osint". Plan research for an organizer-provided username.
Resultado esperado:
- Start with exact username searches and record profile identifiers.
- Check archived profile pages for rename evidence.
- Compare only challenge-relevant details across confirmed accounts.
- Document false positives and stop at unrelated personal information.
Usando "ctf-osint". Analyze a challenge image with a mirrored shop sign.
Resultado esperado:
Flip the image horizontally, isolate the sign, transcribe reliable characters, search the partial phrase, and verify candidates using architecture and surrounding landmarks.
Auditoría de seguridad
Riesgo altoMost critical heuristic alerts are false positives caused by Markdown examples rather than an executable payload. However, the skill includes active scanning, authenticated token use, hidden-file probing, physical tracking, account targeting, and exploit-assisted pivots. These dual-use workflows require substantial authorization and privacy controls before publication.
Preocupaciones de seguridad confirmadas (16)
Mostrar los 16 problemas confirmados
Elementos de revisión de capacidades (26)
Estas son capacidades locales reales que pueden esperarse para esta habilidad, por lo que requieren revisión, pero no se cuentan como comportamiento malicioso confirmado.
Factores de riesgo
🌐 Acceso a red (45)
🔑 Variables de entorno (2)
⚙️ Comandos externos (30)
📁 Acceso al sistema de archivos (4)
Patrones detectados
Compartir y citar este informe
Comparte el informe de evaluación versionado, la insignia neutral, la tarjeta insertable y las citas. Skillstore presenta evidencias sin decidir si este Skill es seguro.
Copiar enlace del informe
https://skillstore.io/skills/ljagiello-ctf-osint/audits/2?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportInsignia Markdown
[](https://skillstore.io/skills/ljagiello-ctf-osint?utm_source=security_passport_badge)Insignia HTML
<a href="https://skillstore.io/skills/ljagiello-ctf-osint?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/ljagiello-ctf-osint/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Tarjeta para insertar
<iframe src="https://skillstore.io/embed/skills/ljagiello-ctf-osint.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Citas académicas (APA · BibTeX · CFF)
Cita APA
ljagiello. (2026). ctf-osint security audit report (audit version 2) [Author version unspecified]. Skillstore. https://skillstore.io/skills/ljagiello-ctf-osint/audits/2Cita BibTeX
@techreport{ljagiello-ljagiello-ctf-osint-2026,
author = {ljagiello},
title = {ctf-osint security audit report (audit version 2)},
institution = {Skillstore},
year = {2026},
number = {2},
url = {https://skillstore.io/skills/ljagiello-ctf-osint/audits/2},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "ctf-osint security audit report (audit version 2)"
version: "unspecified"
type: report
authors:
- name: "ljagiello"
date-released: "2026-08-15"
url: "https://skillstore.io/skills/ljagiello-ctf-osint/audits/2"
identifiers:
- type: other
value: "skillstore:ljagiello-ctf-osint:audit:2"
description: "Skillstore immutable audit report identifier"
Puntuación de Skillstore
Por qué esta puntuación Confianza de la evidencia: MedioLo que puedes crear
Trace a Challenge Persona
Correlate organizer-provided usernames across public profiles and archives while recording evidence and false positives.
Geolocate Challenge Media
Combine metadata, signs, landmarks, maps, and image matching to identify a location from supplied media.
Investigate CTF Infrastructure
Review authorized DNS, WHOIS, archives, repository history, and service metadata for challenge clues.
Prueba estos prompts
Identify this challenge clue: [CLUE]. Explain likely formats, safe validation steps, and what evidence would confirm each interpretation.
Create an authorized CTF research plan for username [USERNAME]. Prioritize public sources, note false positives, and avoid collecting unrelated personal data.
Analyze the supplied challenge image. List visible geographic signals, propose candidate regions, and design a verification sequence using metadata, maps, and reverse search.
For authorized CTF domain [DOMAIN], correlate DNS, WHOIS, archives, certificates, and repository evidence. Ask before any active probe and document uncertainty.
Mejores prácticas
- Confirm written authorization and scope before sending requests or probing services.
- Record source URLs, timestamps, confidence, and alternative explanations for every conclusion.
- Minimize personal data collection and redact tokens, credentials, and unrelated identities.
Evitar
- Do not scan public hosts because they resemble a CTF target.
- Do not bypass privacy controls or infer a person's home from fitness routes.
- Do not place user tokens or API secrets directly in commands, prompts, or reports.
Preguntas frecuentes
Does this skill perform searches automatically?
Does it require internet access?
Can it solve non-CTF investigations?
Which tools may be required?
How should API keys and tokens be handled?
How reliable are OSINT results?
Detalles del desarrollador
Autor
ljagielloLicencia
MIT
Revisión de Skillstore
r1
Aviso de versión
El autor no declaró una versión.
Repositorio
https://github.com/ljagiello/ctf-skills/tree/d6662d26b5ed3caa56f5eaf6eb887964f3747162/ctf-osintRef.
ba0224440a0286a68c9ef7d65e409a580b885eba
Actualidad del mantenimiento
16/8/2026
Uso
0 descargas · 0 vistas
Estructura de archivos