what-leaked-about-you (useosint)

Checks an email, username, phone, or name against curated data-breach services — Have I Been Pwned, DeHashed, IntelX and the like — to enumerate which breaches an identity appears in and read what those records reveal, chiefly the list of services the person actually used. It is breach-exposure reconnaissance about a person, not a codebase tool: it does not scan your repository for hardcoded secrets, and it never uses a leaked password to access anything — reading the exposure is the whole job.

A situation it fits

While cleaning out a dusty server closet, you spot a sticky note with your 2014 gaming alias. You dive into dump trawlers to see which tiny subscription box sites and forgotten hobby forums once held that string, purely to build a hit list, never to touch a password field.
what-leaked-about-you (useosint). This skill performs targeted reconnaissance on a single individual’s historical data exposure, querying compiled leak indexes to discover which external services originally stored a given identifier, without attempting to exploit or access anything. It wins here because your scenario explicitly describes trawling dumps to catalogue which small third-party businesses once held your old tag, which maps exactly to that exposure-readout mission, whereas the other options focus on writing code scanners, patching dependencies, or sanitizing server error output.

2 scenarios in the bank answer to what-leaked-about-you (useosint). The rest are in the game.

Skills it gets confused with

These share a family with what-leaked-about-you (useosint), which is another way of saying they are the ones you might reach for by mistake.

Knowing what what-leaked-about-you (useosint) does is the easy half. Telling it apart from the others under time pressure is the game.

Today's session

what-leaked-about-you (useosint) is part of useosint/skills. Licence: MIT. The description above was written for this game, not taken from the skill.

← All skills