🗂️
DataShell

Secrets In File Metadata

by useosint

Secrets In File Metadata is a Data skill for Claude Code, published by useosint in osint-skills.

12 stars1 forkson useosint/osint-skillsAdded 2026/08/12+200% in starsRepository updated 2026/08/03
agent-skillsai-agentsclaudeclaude-skillscursorcursor-skillscybersecuritydigital-forensicsdue-diligencegeointinformation-gatheringinfosecinvestigationopen-source-intelligenceosintosint-toolspentestingreconnaissancesocmintthreat-intelligence
Install in seconds
Install Secrets In File Metadata
Copy Secrets In File Metadata into your Claude Code skills folder. Run the command in your terminal, or review the source on GitHub before installing.
terminal
npx degit https://github.com/useosint/osint-skills/tree/main/skills/secrets-in-file-metadata ~/.claude/skills/secrets-in-file-metadata

Requires Node.js. Downloads this skill only — not the rest of the repository — into your Claude Code skills folder.

Without Node.js

git clone https://github.com/useosint/osint-skills.git

Clones the whole repository, then copy the skill’s own directory into your skills folder yourself.

In this catalog

Source file
skills/secrets-in-file-metadata/SKILL.md in useosint/osint-skills
Installs to
~/.claude/skills/secrets-in-file-metadata
Collection
One of 25 skills cataloged from this repository
Category
Data668 skills

What Secrets In File Metadata does

Secrets In File Metadata extracts EXIF, XMP, IPTC, Office, and PDF metadata with exiftool to identify device details, timestamps, locations, and provenance clues. Use it when checking who created a file, where a photo was taken, or whether a document was edited.

Secrets In File Metadata is cataloged under Data on DirSkills. Secrets In File Metadata comes from a repository tagged agent-skills, ai-agents, claude, claude-skills and cursor.

Documentation

README

Secrets in file metadata

The fastest lead in an investigation is often already inside the file: GPS to six decimal places, a camera serial that ties four "unrelated" images to one body, a document author who is a real employee, a template path containing a corporate share name.

Two things beginners get wrong. Absent metadata is not suspicious — it is the normal state of anything that passed through a social platform. And present metadata is not proof: every tag is a claim written by whatever software touched the file last, and all of it is editable with one command.

Where to look first, given what you have

This is the opening of the README. Read the full README on GitHub.

Frequently asked about Secrets In File Metadata

  • What else does useosint publish alongside Secrets In File Metadata?

    Secrets In File Metadata is one of 25 skills that DirSkills catalogs from useosint/osint-skills, the repository it ships in. Its siblings there include Dig Through Data Brokers, Find Anyone and Find Exposed Servers. Each one is a separate skill with its own page in this directory, installs the same way Secrets In File Metadata does, and is maintained by useosint in that same repository. The rest of the collection is listed on the useosint/osint-skills page.

  • How does Secrets In File Metadata compare to other Data skills?

    Secrets In File Metadata ranks #664 by stars among the 668 Data skills in this catalog. The most-starred ones next to it are Benchmark Methodology, Jupyter Notebook and Solana. DirSkills ranks by the star count of the repository each skill ships in, so that order reflects how popular those repositories are rather than any review of Secrets In File Metadata against them. Open each page to compare what they document and how they install.

More from useosint/osint-skills

Secrets In File Metadata is one of 25 skills cataloged on DirSkills from useosint/osint-skills.

See all 25 skills
🕵️
3w ago

Dig Through Data Brokers

Dig Through Data Brokers uses people-search sites and public records to turn a name into candidate addresses, phones, relatives, and background details, then confirm them against primary sources. Use it for skip tracing, reverse address lookups, self-audits, and broker data removal.
Automation
121
🕵️
3w ago

Find Anyone

Find Anyone builds a sourced profile of one specific person from public records, professional profiles, court filings, and other open sources. It is used to identify, verify, or background-check someone while avoiding name-mixups.
AI Engineering
121
🔎
3w ago

Find Exposed Servers

Find Exposed Servers uses Shodan, Censys, and similar scan data to identify internet-facing hosts, ports, services, and devices without touching the target. Use it for exposure checks, origin-IP pivots, and Shodan query syntax.
Automation
121
🔎
3w ago

Find Hidden Subdomains

Find Hidden Subdomains enumerates an organization’s subdomains and sibling domains from Certificate Transparency logs and passive DNS without sending traffic to the target. Use it to map hostnames, find staging or admin systems, and spot newly issued certificates.
Automation
121
🕵️
3w ago

Find Leaks In The Wild

Find Leaks In The Wild helps check whether a name, email, domain, or credential is circulating in pastes, forums, and Telegram, and whether a claimed leak is genuine or a recycled combolist. Use it for breach triage, threat intelligence, and leak monitoring.
Automation
121
🖼️
3w ago

Find The Original Image

Find The Original Image uses multiple reverse image search engines to trace an image to its earliest known publication and read the source page. Use it to identify photos, logos, places, profile pictures, reposts, or video keyframes.
Automation
121