Run OhSINT's ACTIVE reconnaissance funnel (subfinder/crtsh → naabu → httpx → katana → nuclei) against an authorized target. Use ONLY when the user wants active scanning that touches the target directly AND has written authorization. Touches the target — requires a stated authorization reason.
Run OhSINT's passive reconnaissance pipelines against a domain — subdomain takeover, historical URL harvest, secret surface discovery, JS analysis, or the full passive sweep. Use for any "recon this domain" / "what's exposed" request that should NOT touch the target. No authorization gate.
Profile an individual from a username, email, or full-name seed using OhSINT (sherlock + maigret + holehe). Use when the user wants to build a subject profile of a specific person. Passive, but profiling a person requires a stated consent reason.
Assess a vendor or third party's external security posture as a graded A–F risk scorecard. Use when the user wants to evaluate a counterparty/supplier rather than hunt bugs. Passive — no authorization gate.
Ingest an OhSINT report.json into the persistent wiki knowledge base and drive the LLM synthesis pass. Use after ANY scan completes, or when the user wants findings added to the wiki / cross-correlated with past engagements. This is OhSINT's episodic memory.