Skip to content
Back to skills

Username Recon

ASecurity

Check usernames across sites with Sherlock (OSINT).

  • 10 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 23, 2026
ai-agentsgobashgitdocumentation

Works with

  • cli

Security analysis

A100/100

Scanned October 6, 2026

npx -y skills add fmind/dot --skill username-recon --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Username Recon?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Username Recon
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/fmind-username-recon/badge)](https://www.skillsdirectory.com/skills/fmind-username-recon)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: username-recon
description: "Check usernames across sites with Sherlock (OSINT)."
license: MIT
metadata:
  kind: task
  author: Médéric HURIER (Fmind)
  source: github.com/fmind/dot/tree/main/skills/username-recon
  created: "2026-09-16"
  updated: "2026-10-05"
---

# Public Username Reconnaissance

Use `sherlock-project/sherlock`, distributed as `sherlock-project`, for public username OSINT checks within the requested scope. Keep usernames, sites, time window, and stop conditions explicit, and stop on scope escape or unexpected impact; this reconnaissance authorizes neither exploitation nor other techniques.

## Workflow

1. **Pin the request scope**: establish the exact usernames, selected sites, purpose, and output destination from the request. Treat a username match as a lead, not proof of a person's identity.
1. **Pin and inspect a reviewed release**: inspect `uvx --from 'sherlock-project==<version>' sherlock --help` and `--version`, resolving `<version>` to a reviewed exact release. This pins Sherlock, not its entire dependency graph; use a locked environment when repeatable dependencies are required. Prefer installed help because published website examples may lag the CLI.
1. **Run selected sites with fixed definitions**: review the selected site's destination and detection rule in that release's bundled definitions. Use `--local` to keep those definitions fixed; it does not make the account lookup offline. Run only the selected sites, with a bounded per-request timeout, in a private output directory. For one authorized username, adapt:
   ```bash
   uvx --from 'sherlock-project==<version>' sherlock <username> --local --site GitHub --timeout 10 --output results.txt --txt
   ```
1. **Verify each reported match**: review reported matches against the public profile URL and the site's current response behavior. Record confirmed presence, not-found, and indeterminate errors separately; do not convert timeouts or blocks into absence.
1. **Minimize retained evidence**: retain only the evidence needed for the task and report confidence and lookup date. Test parsing changes with saved HTTP fixtures instead of repeatedly querying real accounts.

## Gotchas

- **A hit is not an identity**: similar handles can belong to unrelated people; do not infer identity, private attributes, or contact details from a hit.
- **Verify export flags before automating**: `--json` selects site definitions; it is not a JSON result-output switch. `--output` only names the file that `--txt` writes, and that file lists claimed URLs only; record not-found and errors from the run output. Verify export flags before automating them.
- **Site definitions drift either way**: without `--local`, Sherlock can fetch current site definitions independently of the pinned package. Bundled definitions can become stale, and local mode bypasses upstream exclusion updates: verify each reported match against the current site response before claiming presence.
- **Keep lookups within request scope**: avoid all-site expansion, automatic browsing, or remote site-definition overrides unless the request requires them; a remote definition controls where requests go. Release checks can still contact upstream in local mode.

## Documentation

- [Usage](https://sherlockproject.xyz/usage) · [Source and installation](https://github.com/sherlock-project/sherlock)
- Releases: [Sherlock](https://github.com/sherlock-project/sherlock/releases)
- Upstream ships no consumer Agent Skill (checked 2026-10-04); community packages are not upstream endorsements.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…