{"id":28785,"plugin_id":"plugins_6a972043ba948191848287ee55e51b98","kind":"catalog","collection_source":null,"comparison_source":null,"observed_at":"2026-10-09T00:00:01.850Z","digest":"b6c9445788a096b8decc0cca6affb58ff0b8aabbd618b91bd0925fa2c1dcb6c7","against":4576,"payload":{"canonical_app_id":null,"connector_id":null,"created_at":"2026-09-01T19:32:22.358505Z","discoverability":"LISTED","id":"plugins_6a972043ba948191848287ee55e51b98","is_template":false,"name":"chatgpt-osint","release":{"app_ids":[],"app_manifest":null,"app_templates":[],"description":"Nine skills for authorised organisational OSINT, exposure analysis, monitoring and security risk reporting.","display_name":"Authorised OSINT Toolkit","id":"pluginrel_d7b9e49ef61c819189004a90c21fe809","interface":{"brand_color":"#17324D","capabilities":["Plan lawful defensive OSINT reviews","Assess organisational attack surfaces","Review email and cloud exposure","Analyse identity security architecture","Design exposure monitoring processes","Quantify and prioritise security risk","Produce evidence-led security reports"],"category":"Security","composer_icon_dark_url":null,"composer_icon_url":"https://files.openai.com/content?id=file_0000000054c481f4b59b91f5ae05ab2f","default_prompt":"Plan a lawful defensive OSINT review.","default_prompts":["Plan a lawful defensive OSINT review.","Assess these supplied exposure findings and prioritise remediation.","Turn these confirmed findings into an executive security report."],"developer_name":"Robert Lane","logo_url":"https://files.openai.com/content?id=file_00000000c47c81f4bd6f1bdeda5908c4","logo_url_dark":null,"long_description":"A nine-skill toolkit for authorised organisational OSINT, attack-surface analysis, email and cloud exposure review, identity-security assurance, monitoring design, risk quantification and evidence-led reporting. The replacement planning, identity and exposure-analysis skills exclude credentials, account enumeration, authentication testing, exploitation, access-control bypass and surveillance.","plugin_category_id":"security","privacy_policy_url":null,"screenshot_urls":[],"short_description":"Authorised exposure analysis","terms_of_service_url":null,"website_url":null},"keywords":["defensive-osint","attack-surface","exposure-analysis","security","risk"],"onboarding_skill_name":null,"requires_local_executor":false,"skills":[{"description":"Assess attributable cloud storage, SaaS, package-registry and cloud-native exposure using passive or read-only methods. Use only for owned or explicitly authorised targets; exclude credential submission, exploitation and control-plane access.","interface":{"brand_color":"#17324D","default_prompt":"Use $cloud-saas-exposure to help with an explicitly authorised defensive OSINT task.","display_name":"Cloud and SaaS Exposure","icon_large_url":null,"icon_small_url":null,"iconography":"radar","short_description":"Assess attributable cloud and SaaS exposure"},"name":"cloud-saas-exposure","plugin_release_skill_id":"pluginrsk_6a972d8f2d9081918c98368aa398e19d"},{"description":"Design authorised re-scan, diff, finding-lifecycle and public threat-intelligence monitoring workflows. Use for exposure monitoring programmes and alert tuning; do not schedule or contact third-party targets without explicit authority.","interface":{"brand_color":"#17324D","default_prompt":"Use $continuous-exposure-monitoring to help with an explicitly authorised defensive OSINT task.","display_name":"Continuous Exposure Monitoring","icon_large_url":null,"icon_small_url":null,"iconography":"radar","short_description":"Design repeatable exposure monitoring programmes"},"name":"continuous-exposure-monitoring","plugin_release_skill_id":"pluginrsk_6a972d9153c481919d35aa71e9904f55"},{"description":"Analyse supplied security findings and lawfully accessible public organisational information to identify defensive exposure and remediation priorities. Use for evidence synthesis and assurance; not for scanning, account discovery, credential activity, exploitation or surveillance.","interface":{"brand_color":"#17324D","default_prompt":"Use $defensive-exposure-analysis to assess these supplied findings safely.","display_name":"Defensive Exposure Analysis","icon_large_url":null,"icon_small_url":null,"iconography":"radar","short_description":"Analyse supplied exposure evidence"},"name":"defensive-exposure-analysis","plugin_release_skill_id":"pluginrsk_6a972d8f2c0c819188232ffbe3540ff9"},{"description":"Plan lawful defensive public-source research and exposure reviews using user-supplied information or permitted public sources. Use for scope, collection planning, evidence standards and deliverables; not for scanning, user enumeration, credential processing, exploitation or surveillance.","interface":{"brand_color":"#17324D","default_prompt":"Use $defensive-osint-planning to plan a lawful passive security review.","display_name":"Defensive OSINT Planning","icon_large_url":null,"icon_small_url":null,"iconography":"search","short_description":"Plan lawful public-source reviews"},"name":"defensive-osint-planning","plugin_release_skill_id":"pluginrsk_6a972d9056a081919b44fcc918316814"},{"description":"Analyse published DNS records to reach a defensible email-spoofability and SPF supply-chain verdict. Use for passive email-domain security reviews; do not send test mail, enumerate recipients or submit credentials.","interface":{"brand_color":"#17324D","default_prompt":"Use $email-domain-security to help with an explicitly authorised defensive OSINT task.","display_name":"Email Domain Security","icon_large_url":null,"icon_small_url":null,"iconography":"radar","short_description":"Assess email spoofing and SPF risks"},"name":"email-domain-security","plugin_release_skill_id":"pluginrsk_6a972d8fc80c81918510ec50bdbd32ea"},{"description":"Convert existing reconnaissance findings into transparent likelihood, impact, FAIR-style loss estimates, risk scores and executive reporting. Use for analysis and communication, not target collection or active testing.","interface":{"brand_color":"#17324D","default_prompt":"Use $exposure-risk-quantification to help with an explicitly authorised defensive OSINT task.","display_name":"Exposure Risk Quantification","icon_large_url":null,"icon_small_url":null,"iconography":"chart","short_description":"Quantify exposure and communicate cyber risk"},"name":"exposure-risk-quantification","plugin_release_skill_id":"pluginrsk_6a972d90b20481919da860b450110cdc"},{"description":"Review user-supplied identity architecture, federation design and control documentation for defensive security gaps. Use for assurance and remediation planning; not for tenant discovery, account enumeration, login testing or credential activity.","interface":{"brand_color":"#17324D","default_prompt":"Use $identity-security-review to review this identity design.","display_name":"Identity Security Review","icon_large_url":null,"icon_small_url":null,"iconography":"radar","short_description":"Review supplied identity architecture"},"name":"identity-security-review","plugin_release_skill_id":"pluginrsk_6a972d8f336881918839005bc4429a51"},{"description":"Map an organisation from verified legal entities to attributable domains, ASNs, netblocks and public services. Use for authorised corporate-footprint and attack-surface discovery while separating candidates from proven ownership and scan scope.","interface":{"brand_color":"#17324D","default_prompt":"Use $org-attack-surface to help with an explicitly authorised defensive OSINT task.","display_name":"Organisation Attack Surface","icon_large_url":null,"icon_small_url":null,"iconography":"radar","short_description":"Map attributable organisational internet assets"},"name":"org-attack-surface","plugin_release_skill_id":"pluginrsk_6a972d9127208191b4a37de62c112bdd"},{"description":"Run the packaged deterministic external OSINT workflow against an owned or explicitly authorised domain, producing evidence and a workbook. Require scope confirmation before execution, keep discovered sibling assets out of scope, and never auto-run active exploitation.","interface":{"brand_color":"#17324D","default_prompt":"Use $osint-autopilot to help with an explicitly authorised defensive OSINT task.","display_name":"OSINT Autopilot","icon_large_url":null,"icon_small_url":null,"iconography":"radar","short_description":"Run gated authorised OSINT workflows"},"name":"osint-autopilot","plugin_release_skill_id":"pluginrsk_6a972d904b888191822f0c82732c10ca"}],"version":"1.1.0"},"scope":"GLOBAL","status":"ENABLED"},"changes":[{"path":"/discoverability","type":"changed","before":"UNLISTED","after":"LISTED"}],"summary":"Fields changed: 1. /discoverability.","summary_kind":"deterministic","summary_metadata":{}}