Claude Market
Menu
SkillsMCPPluginsSubmit MCPSkillPluginMCPMCP, plugin, or skillAdvertise
Claude Market
SkillsMCPPluginsSubmit MCPSkillPluginMCPMCP, plugin, or skillAdvertise

Featured

Deploy OpenClaw in 60 seconds — 20% off logoDeploy OpenClaw in 60 seconds — 20% off

Launch OpenClaw on Hostinger in about 60 seconds and keep your agent live 24/7. Our referral link gives you 20% off, no coupon code needed.

Launch on Hostinger →
Run your Hermes agent on Hostinger, fully managed logoRun your Hermes agent on Hostinger, fully managed

Launch Hermes on Hostinger in one click, fully managed, no VPS knowledge needed. Use code ZACAARON10 for 10% off.

Launch on Hostinger →
Crawl and scrape any site into clean data, 10% off logoCrawl and scrape any site into clean data, 10% off

Firecrawl crawls and scrapes any site into clean markdown for your agent. Get 1,000 free credits, and new users get 10% off their first purchase.

Try Firecrawl free →
6,000+ web scrapers for your AI agent, start free logo6,000+ web scrapers for your AI agent, start free

Apify gives your agent live web data: 6,000+ prebuilt scrapers and actors, MCP-ready. Sign up free with $5 in usage credits.

Try Apify free →
One API to scrape, enrich, and extract the internet. logoOne API to scrape, enrich, and extract the internet.

Context.dev gives your agents a single API to scrape, enrich, and extract live web data — no proxies, no parsers, no maintenance.

Start building free →
SetupClaw: done-for-you OpenClaw for founders & exec teams logoSetupClaw: done-for-you OpenClaw for founders & exec teams

White-glove OpenClaw for founders and exec teams (4–50+ employees): we install, harden, integrate your tools, and maintain it — secured from day one.

Get it set up for you →
SEO data APIs for your agent, $1 free credit logoSEO data APIs for your agent, $1 free credit

DataForSEO gives your agent live access to SERP results, keyword data, backlinks, and on-page SEO data through one API. New accounts get a $1 credit, good for up to 20,000 keyword or backlink lookups.

Try DataForSEO free →
Reach 48,000+ AI builders

A flat monthly placement in front of developers actively installing AI tools. No lock-in, cancel anytime.

Advertise here →
Deploy OpenClaw in 60 seconds — 20% off logoDeploy OpenClaw in 60 seconds — 20% off

Launch OpenClaw on Hostinger in about 60 seconds and keep your agent live 24/7. Our referral link gives you 20% off, no coupon code needed.

Launch on Hostinger →
Run your Hermes agent on Hostinger, fully managed logoRun your Hermes agent on Hostinger, fully managed

Launch Hermes on Hostinger in one click, fully managed, no VPS knowledge needed. Use code ZACAARON10 for 10% off.

Launch on Hostinger →
Crawl and scrape any site into clean data, 10% off logoCrawl and scrape any site into clean data, 10% off

Firecrawl crawls and scrapes any site into clean markdown for your agent. Get 1,000 free credits, and new users get 10% off their first purchase.

Try Firecrawl free →
6,000+ web scrapers for your AI agent, start free logo6,000+ web scrapers for your AI agent, start free

Apify gives your agent live web data: 6,000+ prebuilt scrapers and actors, MCP-ready. Sign up free with $5 in usage credits.

Try Apify free →
One API to scrape, enrich, and extract the internet. logoOne API to scrape, enrich, and extract the internet.

Context.dev gives your agents a single API to scrape, enrich, and extract live web data — no proxies, no parsers, no maintenance.

Start building free →
SetupClaw: done-for-you OpenClaw for founders & exec teams logoSetupClaw: done-for-you OpenClaw for founders & exec teams

White-glove OpenClaw for founders and exec teams (4–50+ employees): we install, harden, integrate your tools, and maintain it — secured from day one.

Get it set up for you →
SEO data APIs for your agent, $1 free credit logoSEO data APIs for your agent, $1 free credit

DataForSEO gives your agent live access to SERP results, keyword data, backlinks, and on-page SEO data through one API. New accounts get a $1 credit, good for up to 20,000 keyword or backlink lookups.

Try DataForSEO free →
Reach 48,000+ AI builders

A flat monthly placement in front of developers actively installing AI tools. No lock-in, cancel anytime.

Advertise here →
Deploy OpenClaw in 60 seconds — 20% off logoDeploy OpenClaw in 60 seconds — 20% off
Launch on Hostinger →
Run your Hermes agent on Hostinger, fully managed logoRun your Hermes agent on Hostinger, fully managed
Launch on Hostinger →
Crawl and scrape any site into clean data, 10% off logoCrawl and scrape any site into clean data, 10% off
Try Firecrawl free →
6,000+ web scrapers for your AI agent, start free logo6,000+ web scrapers for your AI agent, start free
Try Apify free →
One API to scrape, enrich, and extract the internet. logoOne API to scrape, enrich, and extract the internet.
Start building free →
SetupClaw: done-for-you OpenClaw for founders & exec teams logoSetupClaw: done-for-you OpenClaw for founders & exec teams
Get it set up for you →
SEO data APIs for your agent, $1 free credit logoSEO data APIs for your agent, $1 free credit
Try DataForSEO free →
Reach 48,000+ AI builders
Advertise here →
Skills/useosint/osint-skills/what-leaked-about-you
what-leaked-about-you logo

what-leaked-about-you

useosint/osint-skills
2K installs2 stars
Run it on Hostinger →up to 70% off + an extra 10% with code ZACAARON10Free API →

Installation

npx skills add https://github.com/useosint/osint-skills --skill what-leaked-about-you

Summary

Check and interpret data-breach exposure for an email, username, phone, or name using Have I Been Pwned, the Pwned Passwords k-anonymity range API, DeHashed, IntelX, and Snusbase. Use when checking breach or leak exposure, finding which services an account was registered with, interpreting a combolist or credential dump, assessing credential compromise, or doing a self-audit of leaked personal data.

SKILL.md

What leaked about you

Breach data answers a question nothing else answers cheaply: which services did this identity actually use. That service list is almost always worth more to an investigator than the credentials in the record — and the credentials are the part you must never touch. Using a leaked password is unauthorized access, no matter how public the dump was.

What a record actually contains, and what matters

A breach record is a row from a service's user table. Typical fields: email, username, a password hash (or plaintext, in bad cases), registration date, last login, IP address at signup, display name, date of birth, physical address, security questions, and whatever the service happened to collect.

The metadata beats the credentials, every time:

FieldWhy it matters
Which serviceMembership itself. This person had an account here — a fact you can rarely establish any other way
Registration dateTime-anchors the identity. Sign-up clusters across services link accounts
Username in the recordA handle you did not have. Straight into hunt-a-handle
Signup or last-login IPCoarse geolocation and, more usefully, hosting-vs-residential classification
Display name, DOB, addressIdentity attributes to corroborate elsewhere. Never treat as authoritative
Password patternLinkage evidence, analytically. Never an input to a login form

Field-by-field interpretation: reference/record-fields.md.

Choosing a source

HoldingReach forWhy
An email, need a service listHave I Been PwnedCurated, deduplicated, names the breach and its data classes. Does not return credentials
A password you already hold (yours, or one in scope)HIBP Pwned Passwords range APITells you if the password is in circulation without disclosing it
Need actual field values, or to search by username, phone, IP, or nameKeyed commercial servicesThe only way to pivot into records rather than just detecting membership
A specific dump circulating nowfind-leaks-in-the-wildPaste sites, forums, and channels, before anything indexes them

Have I Been Pwned is the default starting point. It is curated: breaches are verified before loading and data classes are labelled, so a hit means something. Free web lookup for an email; the API is keyed and permits programmatic and domain-wide checks. It deliberately does not hand you passwords.

Pwned Passwords is worth understanding properly because the design is the point. You SHA-1 the password locally, send only the first five hex characters of the hash to the range endpoint, and receive every hash suffix sharing that prefix, with occurrence counts. You match locally. The service never learns which password you asked about. This makes it safe to run against credentials you legitimately hold, and it is the correct tool for a self-audit or a client remediation exercise.

Keyed commercial services — DeHashed, IntelX, and Snusbase are the commonly used ones. What differentiates them:

  • Record-level search across many selector types, returning actual field values.

This is the pivot engine: username, phone, IP, and name searches, not just email.

  • Corpus breadth versus curation. Broader corpora ingest more combolists and

therefore more junk; curated ones miss things. Know which side your source sits on.

  • Some index documents, pastes, darkweb pages, and leaked files rather than

parsed user tables — closer to a search engine over leaked material than to a breach database.

Access model and coverage comparison: reference/source-catalogue.md.

The rule that has no exceptions

Never use a leaked credential to authenticate to anything. Not to "confirm the account exists". Not on a test account. Not on the subject's account with a client's verbal blessing. Credential stuffing is unauthorized access under computer-misuse law in most jurisdictions, and the public availability of the password is not a defence — see ../../ETHICS.md.

The same applies to derived actions: do not attempt password resets, do not use recovered security-question answers, and do not try a recovered password on a different service to test reuse. Reuse is something you infer from data you already hold, never something you test.

The real pivot: service enumeration

Work the breach list as an account map. An email appearing in a gaming forum, a fitness app, and a regional dating service tells you three platforms to investigate, three registration dates, and often three usernames — each one a seed for hunt-a-handle. The services themselves characterise the person: professional, regional, linguistic, and interest signals that no profile page would give you.

Password patterns are linkage evidence when handled correctly. If two records under different identities carry the same distinctive password — a long, non-dictionary, clearly personal string — that is meaningful correlation, and you record it as an analytic observation with the string itself redacted or hashed in your notes. A common password (password1, a keyboard walk, a football team) links nothing; thousands of people share it. Distinctiveness is the whole signal, and the evidence is the coincidence, not the credential.

Hashes are out of scope

Records commonly contain hashes: MD5 or unsalted SHA-1 on old breaches, salted schemes and purpose-built password hashes on newer ones. You will occasionally see plaintext where a service stored it unhashed, and reversible encryption where someone chose badly.

Note the hash type — it dates the breach and characterises the service's security posture, which is genuinely useful in a due-diligence context. Then stop. Cracking a hash produces a credential you are not allowed to use, so the work has no legitimate output. The exception is a self-audit or an authorized security assessment where the password holder is your client, and even then the range API answers the question without cracking anything.

Where this goes wrong

  • Combolist contamination. Most large "breaches" in circulation are

combolists: aggregations of credentials from many sources, deduplicated, reshuffled, and stripped of provenance. A hit in a combolist tells you a pair appeared somewhere, not which service it came from. That destroys the service-enumeration value, which was the point.

  • Recycled and fabricated breaches. Old data gets repackaged under a new

name and sold as fresh. Some "breaches" are wholly invented, or are scrapes of public profiles marketed as a hack. Check whether the alleged source has ever acknowledged an incident, and whether the record structure matches what that service would plausibly store.

  • Breach date is not leak date. Three separate dates matter: when the data

was taken, when it first circulated, and when your source ingested it. They can be years apart. "Appeared in a breach dated X" says the account existed before X, not that it was active then.

  • Absence proves nothing. Not appearing in any corpus means the person's

services were not breached, or the breach was never published, or your source does not carry it.

  • Scrape-vs-breach confusion. A dataset assembled by scraping public

profiles is not evidence of a compromise, and reporting it as one is a factual error that damages a report's credibility.

  • Stale attribution. Email addresses and phone numbers get abandoned and

reassigned. A ten-year-old record may describe someone else entirely.

  • Vendor overlap masquerading as corroboration. Two commercial services

agreeing frequently means they ingested the same dump.

Confidence grading

  • Confirmed — the record appears in a curated source that verified and

attributed the breach, the field structure matches the named service, and a second selector in the record corroborates independently.

  • Probable — a record in a reputable commercial corpus with clear

attribution to a named service and internally consistent fields.

  • Unconfirmed — a combolist hit, an unattributed dump, or a single row with

no corroborating selector. Report the existence of the hit and say plainly that the source is unattributed.

  • Rejected — the alleged source has no plausible incident, the fields do not

match what that service collects, or the data is a public scrape relabelled.

Grade the breach, not just the record. A well-attributed breach makes every row in it more credible; an anonymous compilation makes every row less so.

Worked example

Self-audit for a client using a.mercer@example.com. HIBP returns four breaches. One is a large forum breach from several years back, data classes listed as email addresses, usernames, IP addresses, and password hashes.

The username in that breach is merce_ada, which the client had forgotten using. That handle goes to hunt-a-handle and turns up two live accounts the client did not know were still public — the most valuable output of the exercise and nothing to do with credentials.

The dead end: a commercial source returns a fifth "breach" attributed to a retailer, containing a home address. The retailer has never disclosed an incident, the field layout does not resemble a retail order table, and the same address appears in two data-broker records. Assessed as scraped aggregator data relabelled as a breach. Excluded from the report with the reasoning recorded.

Remediation: passwords the client still uses are checked through the Pwned Passwords range API, so no password leaves the machine. No credential from any record is used anywhere.

Pivots

New selectorSkill
Username recovered from a recordhunt-a-handle
Additional email addresseswhat-an-email-reveals
Phone number in a recordwhose-number-is-this
Signup IPfind-exposed-servers
Name, DOB, address fieldsfind-anyone, dig-through-data-brokers
Corporate domain across many recordsx-ray-a-company
The dump itself, circulatingfind-leaks-in-the-wild
Service list as an entity mapgraph-the-network

Legal and handling notes

Holding breach data is regulated, and more tightly than most OSINT material. Under GDPR and UK data protection law, breach records are personal data — often special-category data — and processing them needs a lawful basis, a defined retention period, and demonstrable data minimisation. Some jurisdictions treat possession of certain stolen data as an offence in itself, irrespective of how you obtained it. Several commercial services restrict their data by licence to specific purposes; read the terms before you put results in a client report.

Practically: pull the minimum fields needed for the objective, do not retain credentials at all, store case material encrypted at rest with access logged, and delete on a schedule you wrote down at the start. If you are working for a subject on their own data, that is the cleanest footing available — and it is the only footing on which testing a password is ever appropriate.

Score

0–100
63/ 100

Grade

C

Popularity15/30

2,029 installs — growing adoption.

Completeness27/30

Documented: full SKILL.md body, description, one-line install. Missing: category/license metadata.

Trust15/25

Community skill with a public GitHub source repository you can review.

Freshness6/15

No update timestamp is tracked for this skill in our catalog.

Scored automatically from popularity, completeness, trust, and freshness — computed only from data in our catalog, never fabricated.

Proud of your score? Add this badge to your README.

Paste a snippet into your GitHub README. The badge updates automatically and links back to this page.

What Leaked About You skill score badge previewScore badge

Markdown

[![What Leaked About You skill](https://www.claudemarket.ai/skills/useosint/osint-skills/what-leaked-about-you/badges/score.svg)](https://www.claudemarket.ai/skills/useosint/osint-skills/what-leaked-about-you)

HTML

<a href="https://www.claudemarket.ai/skills/useosint/osint-skills/what-leaked-about-you"><img src="https://www.claudemarket.ai/skills/useosint/osint-skills/what-leaked-about-you/badges/score.svg" alt="What Leaked About You skill"/></a>

What Leaked About You FAQ

How do I install the What Leaked About You skill?

Run “npx skills add https://github.com/useosint/osint-skills --skill what-leaked-about-you” in your terminal. The skill is added to your agent's skills directory and picked up automatically on the next run — no restart or extra configuration needed.

What does the What Leaked About You skill do?

Check and interpret data-breach exposure for an email, username, phone, or name using Have I Been Pwned, the Pwned Passwords k-anonymity range API, DeHashed, IntelX, and Snusbase. Use when checking breach or leak exposure, finding which services an account was registered with, interpreting a combolist or credential dump, assessing credential compromise, or doing a self-audit of leaked personal data. The full SKILL.md on this page shows the exact instructions the skill gives your agent.

Is the What Leaked About You skill free?

Yes. What Leaked About You is a free, open-source skill published from useosint/osint-skills. As with any third-party skill, review the source repository before installing it into an agent with sensitive access.

Does What Leaked About You work with Claude Code and OpenClaw?

Yes. Skills use the portable SKILL.md format, so What Leaked About You works with Claude Code, OpenClaw, Codex, Hermes, and any other agent that reads SKILL.md skills.

Featured

Deploy OpenClaw in 60 seconds — 20% off logoDeploy OpenClaw in 60 seconds — 20% off

Launch OpenClaw on Hostinger in about 60 seconds and keep your agent live 24/7. Our referral link gives you 20% off, no coupon code needed.

Launch on Hostinger →
Run your Hermes agent on Hostinger, fully managed logoRun your Hermes agent on Hostinger, fully managed

Launch Hermes on Hostinger in one click, fully managed, no VPS knowledge needed. Use code ZACAARON10 for 10% off.

Launch on Hostinger →
Crawl and scrape any site into clean data, 10% off logoCrawl and scrape any site into clean data, 10% off

Firecrawl crawls and scrapes any site into clean markdown for your agent. Get 1,000 free credits, and new users get 10% off their first purchase.

Try Firecrawl free →
6,000+ web scrapers for your AI agent, start free logo6,000+ web scrapers for your AI agent, start free

Apify gives your agent live web data: 6,000+ prebuilt scrapers and actors, MCP-ready. Sign up free with $5 in usage credits.

Try Apify free →
One API to scrape, enrich, and extract the internet. logoOne API to scrape, enrich, and extract the internet.

Context.dev gives your agents a single API to scrape, enrich, and extract live web data — no proxies, no parsers, no maintenance.

Start building free →
SetupClaw: done-for-you OpenClaw for founders & exec teams logoSetupClaw: done-for-you OpenClaw for founders & exec teams

White-glove OpenClaw for founders and exec teams (4–50+ employees): we install, harden, integrate your tools, and maintain it — secured from day one.

Get it set up for you →
SEO data APIs for your agent, $1 free credit logoSEO data APIs for your agent, $1 free credit

DataForSEO gives your agent live access to SERP results, keyword data, backlinks, and on-page SEO data through one API. New accounts get a $1 credit, good for up to 20,000 keyword or backlink lookups.

Try DataForSEO free →
Reach 48,000+ AI builders

A flat monthly placement in front of developers actively installing AI tools. No lock-in, cancel anytime.

Advertise here →
Deploy OpenClaw in 60 seconds — 20% off logoDeploy OpenClaw in 60 seconds — 20% off

Launch OpenClaw on Hostinger in about 60 seconds and keep your agent live 24/7. Our referral link gives you 20% off, no coupon code needed.

Launch on Hostinger →
Run your Hermes agent on Hostinger, fully managed logoRun your Hermes agent on Hostinger, fully managed

Launch Hermes on Hostinger in one click, fully managed, no VPS knowledge needed. Use code ZACAARON10 for 10% off.

Launch on Hostinger →
Crawl and scrape any site into clean data, 10% off logoCrawl and scrape any site into clean data, 10% off

Firecrawl crawls and scrapes any site into clean markdown for your agent. Get 1,000 free credits, and new users get 10% off their first purchase.

Try Firecrawl free →
6,000+ web scrapers for your AI agent, start free logo6,000+ web scrapers for your AI agent, start free

Apify gives your agent live web data: 6,000+ prebuilt scrapers and actors, MCP-ready. Sign up free with $5 in usage credits.

Try Apify free →
One API to scrape, enrich, and extract the internet. logoOne API to scrape, enrich, and extract the internet.

Context.dev gives your agents a single API to scrape, enrich, and extract live web data — no proxies, no parsers, no maintenance.

Start building free →
SetupClaw: done-for-you OpenClaw for founders & exec teams logoSetupClaw: done-for-you OpenClaw for founders & exec teams

White-glove OpenClaw for founders and exec teams (4–50+ employees): we install, harden, integrate your tools, and maintain it — secured from day one.

Get it set up for you →
SEO data APIs for your agent, $1 free credit logoSEO data APIs for your agent, $1 free credit

DataForSEO gives your agent live access to SERP results, keyword data, backlinks, and on-page SEO data through one API. New accounts get a $1 credit, good for up to 20,000 keyword or backlink lookups.

Try DataForSEO free →
Reach 48,000+ AI builders

A flat monthly placement in front of developers actively installing AI tools. No lock-in, cancel anytime.

Advertise here →
Deploy OpenClaw in 60 seconds — 20% off logoDeploy OpenClaw in 60 seconds — 20% off
Launch on Hostinger →
Run your Hermes agent on Hostinger, fully managed logoRun your Hermes agent on Hostinger, fully managed
Launch on Hostinger →
Crawl and scrape any site into clean data, 10% off logoCrawl and scrape any site into clean data, 10% off
Try Firecrawl free →
6,000+ web scrapers for your AI agent, start free logo6,000+ web scrapers for your AI agent, start free
Try Apify free →
One API to scrape, enrich, and extract the internet. logoOne API to scrape, enrich, and extract the internet.
Start building free →
SetupClaw: done-for-you OpenClaw for founders & exec teams logoSetupClaw: done-for-you OpenClaw for founders & exec teams
Get it set up for you →
SEO data APIs for your agent, $1 free credit logoSEO data APIs for your agent, $1 free credit
Try DataForSEO free →
Reach 48,000+ AI builders
Advertise here →

Categories

No Code
View on GitHub

Recommended skills

Browse all →
find-skills logo

find-skills

vercel-labs/skills

2.8M installsInstall
frontend-design logo

frontend-design

anthropics/skills

732K installsInstall
grill-me logo

grill-me

mattpocock/skills

730K installsInstall
grill-with-docs logo

grill-with-docs

mattpocock/skills

620K installsInstall
agent-browser logo

agent-browser

vercel-labs/agent-browser

613K installsInstall
vercel-react-best-practices logo

vercel-react-best-practices

vercel-labs/agent-skills

600K installsInstall

Related guides

Hand-picked reading to help you choose, install, and use agent skills.

GuideBest Security Skills For AI AgentsGuideHow To Find The Right Openclaw Skill For Your ProjectGuideBest Openclaw Skills 2026

Skills by category

FrontendBackend & APIsTesting & QASecurityDevOps & CI/CDMCP & ToolingAutomationData & Analysis+20 more

MCP servers by category

AI & MLDeveloper ToolsVector & MemoryFiles & DocsDatabasesFinance & PaymentsBrowser & ScrapingCommunication+8 more

Plugins by category

developmentproductivitycommunicationdesignsecuritydatabaseworkflowcompliance+34 more

The Agent Stack

Weekly Claude Code, Agent SDK, and MCP moves worth your time — free.

Claude Market

AI agent skills directory, marketplace, and workflow hub for OpenClaw, Hermes Agent, Claude Code, Codex, and MCP-powered operator stacks.

Independent project, not affiliated with Anthropic.

Resources

  • Browse Skills
  • Browse MCP Servers
  • Browse Plugins

More

  • Submit a Tool
  • Advertise
  • Free Tools
  • API
  • Shipping
  • Contact
  • Terms
  • Privacy
© 2026 Claude Market · Not affiliated with Anthropic
Fazier badgeFeatured on Twelve ToolsFeatured on Wired BusinessRemote OpenClaw - Featured on AI Agents DirectoryListed on Turbo0Featured on Uneed