investigate-without-getting-made
Protect Your Identity During Online Investigations
Online investigations can expose researchers through accounts, networks, browser fingerprints, timing, and metadata. This skill provides threat modeling, compartmentation, persona controls, and exposure logging.
Остановитесь и запросите подтверждение перед установкой.
Проверьте план и получите явное согласие пользователя перед изменением файлов.
Установить с помощью моего Агента
Скопируйте этот запрос в своего Агента. Он содержит каноническую страницу Skill и манифест.
Review the Skillstore skill "investigate-without-getting-made" from https://skillstore.io/skills/useosint-investigate-without-getting-made.md and its manifest at https://skillstore.io/api/skills/useosint-investigate-without-getting-made/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.Ваш Агент по-прежнему должен показать план и запросить все подтверждения, требуемые политикой безопасности.
Ресурсы для AI-агентов
Используйте эти ссылки, когда AI-агенту, crawler или script нужен чистый контекст вместо полной страницы.
Протестировать
Использование «investigate-without-getting-made». Assess a public company website review from an office network.
Ожидаемый результат:
Risk: the company can associate the visit with the employer ASN. Use a dedicated browser profile and approved non-corporate egress. Grade the visit anonymous contact.
Использование «investigate-without-getting-made». Prepare to view a subject profile while signed into a personal account.
Ожидаемый результат:
Do not proceed. The platform may expose the viewer identity or create contact suggestions. Confirm current notification behavior using accounts you control.
Использование «investigate-without-getting-made». Record an accidental attributed visit.
Ожидаемый результат:
- Stop further collection from the exposed identity.
- Record the identity, timestamp, action, and visible information.
- Notify the case owner and reassess the collection plan.
Аудит безопасности
Высокий рискAll 18 static findings are false positives caused by Markdown references and descriptive prose. The relative path is a documentation link, not filesystem access. However, detailed persona creation and detection-evasion guidance creates high dual-use risk despite legal warnings and observation-only limits.
Подтверждённые проблемы безопасности (1)
Факторы риска
⚙️ Внешние команды (11)
📁 Доступ к файловой системе (1)
Поделиться и цитировать этот отчет
Делитесь версионным отчетом об оценке, нейтральным значком, встраиваемой карточкой и цитатами. Skillstore публикует доказательства, не решая, безопасен ли этот Skill.
Копировать ссылку на отчёт
https://skillstore.io/skills/useosint-investigate-without-getting-made/audits/1?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportЗначок Markdown
[](https://skillstore.io/skills/useosint-investigate-without-getting-made?utm_source=security_passport_badge)Значок HTML
<a href="https://skillstore.io/skills/useosint-investigate-without-getting-made?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/useosint-investigate-without-getting-made/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Встраиваемая карточка
<iframe src="https://skillstore.io/embed/skills/useosint-investigate-without-getting-made.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Академические ссылки (APA · BibTeX · CFF)
Цитата APA
useosint. (2026). investigate-without-getting-made security audit report (audit version 1) [Author version unspecified]. Skillstore. https://skillstore.io/skills/useosint-investigate-without-getting-made/audits/1Цитата BibTeX
@techreport{useosint-useosint-investigate-without-getting-made-2026,
author = {useosint},
title = {investigate-without-getting-made security audit report (audit version 1)},
institution = {Skillstore},
year = {2026},
number = {1},
url = {https://skillstore.io/skills/useosint-investigate-without-getting-made/audits/1},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "investigate-without-getting-made security audit report (audit version 1)"
version: "unspecified"
type: report
authors:
- name: "useosint"
date-released: "2026-08-03"
url: "https://skillstore.io/skills/useosint-investigate-without-getting-made/audits/1"
identifiers:
- type: other
value: "skillstore:useosint-investigate-without-getting-made:audit:1"
description: "Skillstore immutable audit report identifier"
Оценка Skillstore
Почему такая оценка Достоверность доказательств: СреднийЧто вы можете построить
Protect Sensitive Reporting
Plan source research while limiting account, browser, network, and metadata exposure.
Prepare Due Diligence
Assess whether online collection could alert a company, executive, or monitored service.
Control Case Attribution
Document authorization, compartment research environments, and grade exposure after each collection action.
Попробуйте эти промпты
Create a pre-action OPSEC checklist for researching public websites. Use only passive sources and identify what the subject could observe.
Compare a normal browser, dedicated profile, and dedicated virtual machine for this authorized investigation: [describe case]. Recommend the least complex adequate setup.
Review this collection plan: [plan]. Map account, IP, ASN, browser, TLS, timing, contact-graph, preview, and metadata exposure. Suggest safer passive alternatives.
Build an authorized investigation OPSEC plan for [objective]. Include threat actors, consequences, compartmentation, legal review points, exposure grades, failure responses, and retirement criteria.
Лучшие практики
- Document authorization, purpose, platform scope, and retirement criteria before creating any research account.
- Prefer archives, registries, and other passive sources before contacting target-controlled infrastructure.
- Log each exposure event immediately and notify the case owner when attribution occurs.
Избегать
- Do not sign into personal accounts inside a research environment.
- Do not use found credentials, password-reset flows, or false pretexts to access closed systems.
- Do not impersonate real people or use research personas to elicit private information.
Часто задаваемые вопросы
Does this skill guarantee anonymity?
When is a research persona appropriate?
Should I use Tor for every investigation?
Is a private browser window enough?
What should I do after accidental attribution?
Does this skill provide legal approval?
Сведения для разработчиков
Автор
useosintЛицензия
MIT
Ревизия Skillstore
r1
Примечание о версии
Автор не указал версию.
Ссылка
76c3621ba67d9236f7e0674bbf2a2ecc2696e20c
Актуальность поддержки
03.08.2026
Использование
0 загрузок · 0 просмотров
Структура файлов