investigate-without-getting-made
Protect Your Identity During Online Investigations
Online investigations can expose researchers through accounts, networks, browser fingerprints, timing, and metadata. This skill provides threat modeling, compartmentation, persona controls, and exposure logging.
Detente y solicita confirmación antes de instalar.
Revisa el plan y obtén el consentimiento explícito del usuario antes de modificar archivos.
Instalar con mi Agente
Copia esta solicitud en tu Agente. Incluye la página canónica del Skill y el manifiesto.
Review the Skillstore skill "investigate-without-getting-made" from https://skillstore.io/skills/useosint-investigate-without-getting-made.md and its manifest at https://skillstore.io/api/skills/useosint-investigate-without-getting-made/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.Tu Agente debe seguir mostrando su plan y solicitar cualquier confirmación exigida por la política de seguridad.
Recursos legibles por agentes
Usa estos enlaces cuando un agente de IA, crawler o script necesite contexto limpio en vez de leer la página completa.
Pruébalo
Usando "investigate-without-getting-made". Assess a public company website review from an office network.
Resultado esperado:
Risk: the company can associate the visit with the employer ASN. Use a dedicated browser profile and approved non-corporate egress. Grade the visit anonymous contact.
Usando "investigate-without-getting-made". Prepare to view a subject profile while signed into a personal account.
Resultado esperado:
Do not proceed. The platform may expose the viewer identity or create contact suggestions. Confirm current notification behavior using accounts you control.
Usando "investigate-without-getting-made". Record an accidental attributed visit.
Resultado esperado:
- Stop further collection from the exposed identity.
- Record the identity, timestamp, action, and visible information.
- Notify the case owner and reassess the collection plan.
Auditoría de seguridad
Riesgo altoAll 18 static findings are false positives caused by Markdown references and descriptive prose. The relative path is a documentation link, not filesystem access. However, detailed persona creation and detection-evasion guidance creates high dual-use risk despite legal warnings and observation-only limits.
Preocupaciones de seguridad confirmadas (1)
Factores de riesgo
⚙️ Comandos externos (11)
📁 Acceso al sistema de archivos (1)
Compartir y citar este informe
Comparte el informe de evaluación versionado, la insignia neutral, la tarjeta insertable y las citas. Skillstore presenta evidencias sin decidir si este Skill es seguro.
Copiar enlace del informe
https://skillstore.io/skills/useosint-investigate-without-getting-made/audits/1?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportInsignia Markdown
[](https://skillstore.io/skills/useosint-investigate-without-getting-made?utm_source=security_passport_badge)Insignia HTML
<a href="https://skillstore.io/skills/useosint-investigate-without-getting-made?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/useosint-investigate-without-getting-made/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Tarjeta para insertar
<iframe src="https://skillstore.io/embed/skills/useosint-investigate-without-getting-made.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Citas académicas (APA · BibTeX · CFF)
Cita APA
useosint. (2026). investigate-without-getting-made security audit report (audit version 1) [Author version unspecified]. Skillstore. https://skillstore.io/skills/useosint-investigate-without-getting-made/audits/1Cita BibTeX
@techreport{useosint-useosint-investigate-without-getting-made-2026,
author = {useosint},
title = {investigate-without-getting-made security audit report (audit version 1)},
institution = {Skillstore},
year = {2026},
number = {1},
url = {https://skillstore.io/skills/useosint-investigate-without-getting-made/audits/1},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "investigate-without-getting-made security audit report (audit version 1)"
version: "unspecified"
type: report
authors:
- name: "useosint"
date-released: "2026-08-03"
url: "https://skillstore.io/skills/useosint-investigate-without-getting-made/audits/1"
identifiers:
- type: other
value: "skillstore:useosint-investigate-without-getting-made:audit:1"
description: "Skillstore immutable audit report identifier"
Puntuación de Skillstore
Por qué esta puntuación Confianza de la evidencia: MedioLo que puedes crear
Protect Sensitive Reporting
Plan source research while limiting account, browser, network, and metadata exposure.
Prepare Due Diligence
Assess whether online collection could alert a company, executive, or monitored service.
Control Case Attribution
Document authorization, compartment research environments, and grade exposure after each collection action.
Prueba estos prompts
Create a pre-action OPSEC checklist for researching public websites. Use only passive sources and identify what the subject could observe.
Compare a normal browser, dedicated profile, and dedicated virtual machine for this authorized investigation: [describe case]. Recommend the least complex adequate setup.
Review this collection plan: [plan]. Map account, IP, ASN, browser, TLS, timing, contact-graph, preview, and metadata exposure. Suggest safer passive alternatives.
Build an authorized investigation OPSEC plan for [objective]. Include threat actors, consequences, compartmentation, legal review points, exposure grades, failure responses, and retirement criteria.
Mejores prácticas
- Document authorization, purpose, platform scope, and retirement criteria before creating any research account.
- Prefer archives, registries, and other passive sources before contacting target-controlled infrastructure.
- Log each exposure event immediately and notify the case owner when attribution occurs.
Evitar
- Do not sign into personal accounts inside a research environment.
- Do not use found credentials, password-reset flows, or false pretexts to access closed systems.
- Do not impersonate real people or use research personas to elicit private information.
Preguntas frecuentes
Does this skill guarantee anonymity?
When is a research persona appropriate?
Should I use Tor for every investigation?
Is a private browser window enough?
What should I do after accidental attribution?
Does this skill provide legal approval?
Detalles del desarrollador
Autor
useosintLicencia
MIT
Revisión de Skillstore
r1
Aviso de versión
El autor no declaró una versión.
Ref.
76c3621ba67d9236f7e0674bbf2a2ecc2696e20c
Actualidad del mantenimiento
3/8/2026
Uso
0 descargas · 0 vistas
Estructura de archivos