Privateinvestigator skill

Ethical people-finding and identity verification via parallel research agents across people-search sites, social media, public records, and reverse phone/email/image/username lookups, with confidence-scored results requiring 3+ matching identifiers.

by danielmiessler·MIT license·★ 19,269 Stars on the repo·GitHub ↗

Use now

Files of Privateinvestigator

danielmiessler/main1 file shown
SKILL.md
Show the full text214 lines

Customization

Before executing, check for user customizations at: ~/.claude/LIFEOS/USER/CUSTOMIZATIONS/SKILLS/PrivateInvestigator/

If this directory exists, load and apply any PREFERENCES.md, configurations, or resources found there. These override default behavior. If the directory does not exist, proceed with skill defaults.

🚨 MANDATORY: Voice Notification (REQUIRED BEFORE ANY ACTION)

You MUST send this notification BEFORE doing anything else when this skill is invoked.

  1. Send voice notification:

    curl -s -X POST http://localhost:31337/notify \
      -H "Content-Type: application/json" \
      -d '{"message": "Running the WORKFLOWNAME workflow in the PrivateInvestigator skill to ACTION"}' \
      > /dev/null 2>&1 &
    
  2. Output text notification:

    Running the **WorkflowName** workflow in the **PrivateInvestigator** skill to ACTION...
    

This is not optional. Execute this curl command immediately upon skill invocation.

PrivateInvestigator - Ethical People Finding

What It Does

Finds people and verifies identities using public data only. It covers people-search aggregators, social media, public records, and reverse lookups in parallel, then scores results by confidence (HIGH/MEDIUM/LOW/POSSIBLE) and trusts a match only when 3+ independent identifiers align.

The Problem

Finding a real person from a name, a phone number, or an email is scattered across dozens of sources — people-search sites, county records, court portals, social platforms, reverse-lookup services — and no single one gives you the answer. Common names make it worse: search "John Smith" and you get thousands of people, most of them the wrong one. Run the searches one at a time and you either give up before you've covered enough sources or you act on a single weak match and contact the wrong person. This skill runs the sources in parallel and refuses to call a match real until several independent identifiers line up.

How It Works

Public data only. No hacking, pretexting, or authentication bypass — every technique here is legal and ethical. The work runs as a parallel investigation across the source categories below; findings get cross-checked and confidence-scored before anything is reported. Choose the fan-out breadth the case needs — a common name across many states wants wide parallel coverage, a rare name in one city wants far less.

Workflow Routing

Workflow Trigger File
FindPerson "find person", "locate", "search for [person]", "reconnect", "lost contact" — full parallel-agent investigation Workflows/FindPerson.md
SocialMediaSearch "social media search" — cross-platform social media investigation Workflows/SocialMediaSearch.md
PublicRecordsSearch "public records" — government and official records search Workflows/PublicRecordsSearch.md
ReverseLookup "reverse lookup" — phone, email, image, username searches Workflows/ReverseLookup.md
VerifyIdentity "verify identity" — confirm correct person match Workflows/VerifyIdentity.md

When executing a workflow, output this notification:

Running the **WorkflowName** workflow in the **PrivateInvestigator** skill to ACTION...

When to Activate

Direct People-Finding
  • "find [person]", "locate [person]", "search for [person]"
  • "reconnect with [person]", "looking for lost contact"
  • "find an old friend", "locate a former coworker"
Reverse Lookup
  • "reverse phone lookup", "who owns this email"
  • "reverse image search", "find person by username"
Investigation
  • "background check" (public data only)
  • "what can you find about [person]"
  • "research [person]"

Research Strategy

Done = broad, independent coverage. Every source category below is worked, and no key identifier (address, employer, DOB, family, social handle) rests on a single source. Run the categories in parallel — dispatch research agents concurrently in one message — and scale the fan-out to the case: a common name across many states justifies many parallel agents and spelling/location variants; a rare name in one city needs only a few. Independence is the point, not headcount: aggregators that resell the same database count as one source, so weight toward genuinely distinct origins (social the subject created, government records, unrelated aggregators).

Core Capabilities

1. People Search Aggregators
Service Type Best For
TruePeopleSearch Free Best free option, fresh data
FastPeopleSearch Free Basic lookups, no signup
Spokeo Freemium Social media aggregation (120+ networks)
BeenVerified Paid Comprehensive background data
2. Social Media Investigation
  • Facebook: Google x-ray searches, mutual friends, groups
  • LinkedIn: Boolean search, alumni networks
  • Instagram/Twitter/TikTok: Username patterns, cross-platform correlation
3. Public Records
  • Voter Registration: Most states publicly available
  • Property Records: County assessor/recorder sites
  • Court Records: PACER (federal), state court portals, CourtListener
  • Business Filings: Secretary of State websites
  • Professional Licenses: State licensing boards
4. Reverse Lookup
  • Phone: CallerID, NumLookup, carrier lookup
  • Email: Epieos, Holehe, Hunter.io
  • Image: PimEyes, TinEye, Google/Yandex Images
  • Username: Sherlock, WhatsMyName, Namechk
5. Google Dorking
site:linkedin.com "John Smith" "Software Engineer"
site:facebook.com "lives in" "Austin" "marketing"
filetype:pdf resume "Jane Doe" "San Francisco"

Investigation Methodology

Anchor on whatever foundation identifiers the request gives — full name (and variations/maiden names), approximate age or DOB, last known location, context (school, workplace, relationship) — then pull from every source category until identifiers corroborate. Each discovered fact (phone, email, username, address, relative) is itself a new lead to run back through the sources, and every candidate gets a timeline-consistency and cross-source check before it earns a confidence score. The order is yours; the finish line is a match that survives the 3+-independent-identifier bar below.

Confidence Scoring

Level Criteria Action
HIGH 3+ unique identifiers match across independent sources Safe to contact
MEDIUM 2 identifiers match, timeline consistent Verify before contact
LOW Single source or name-only match Needs more investigation
POSSIBLE Partial match, requires verification Do not act without more data

Dealing with Common Names

  1. Add Specificity - Include location, age, employer, school
  2. Cross-Reference - Match DOB + address patterns across sources
  3. Family Connections - Verify through known relatives
  4. Timeline Analysis - Does the life history make sense?
  5. Multiple Identifiers - Require 3+ matching data points
GREEN ZONE (Allowed)

✅ Search public records (property, court, voter, business) ✅ Access publicly posted social media content ✅ Use people search aggregator sites ✅ Perform reverse lookups on public data ✅ Google dorking with public search operators

RED ZONE (Never Cross)

❌ Access data behind login walls without authorization ❌ Bypass authentication or security measures ❌ Use pretexting or impersonation ❌ Access private databases (credit, financial, medical) ❌ Stalk, harass, or intimidate subjects ❌ Access PI-only databases without license

When to STOP

  • If the purpose shifts to harassment or stalking
  • If the subject has clearly opted out of contact
  • If investigation requires illegal methods
  • If you suspect the requestor has malicious intent

Examples

Example 1: Finding an Old College Friend

User: "Help me find my college roommate from 2005, John Smith from Austin"
→ Routes to FindPerson.md
→ Fans out parallel research across the source categories
→ Cross-references people search + LinkedIn alumni + property records
→ Verifies identity through timeline analysis
→ Reports findings with HIGH confidence

Example 2: Reverse Phone Lookup

User: "Who called from 512-555-1234?"
→ Routes to ReverseLookup.md
→ Runs phone through CallerID, NumLookup
→ Cross-references with people search aggregators
→ Reports owner name, location, carrier

Example 3: Social Media Investigation

User: "Find Jane Doe's social media, she's a marketing professional in Denver"
→ Routes to SocialMediaSearch.md
→ LinkedIn Boolean search + Google x-ray
→ Username enumeration if handle discovered
→ Reports all accounts with MEDIUM/HIGH confidence

Related Documentation:

  • Complete workflow details in Workflows/ directory
  • Integration with Research skill for parallel agent orchestration

Gotchas

  • Ethical framework is mandatory. Legitimate purposes only — reconnection, due diligence, safety. No stalking or harassment.
  • Wide parallel fan-out can hit rate limits on public records APIs. Stagger launches if services throttle.
  • Verify findings across multiple sources. Single-source results are unreliable.

Execution Log

After completing any workflow, append a single JSONL entry:

echo '{"ts":"'$(date -u +%Y-%m-%dT%H:%M:%SZ)'","skill":"PrivateInvestigator","workflow":"WORKFLOW_USED","input":"8_WORD_SUMMARY","status":"ok|error","duration_s":SECONDS}' >> ~/.claude/LIFEOS/MEMORY/SKILLS/execution.jsonl

Replace WORKFLOW_USED with the workflow executed, 8_WORD_SUMMARY with a brief input description, and SECONDS with approximate wall-clock time. Log status: "error" if the workflow failed.

1---
2name: PrivateInvestigator
3version: 1.1.18
4description: "Ethical people-finding and identity verification via parallel research agents across people-search sites, social media, public records, and reverse phone/email/image/username lookups, with confidence-scored results requiring 3+ matching identifiers. USE WHEN find person, locate person, reconnect, lost contact, old friend, reverse phone lookup, who owns this email, reverse image search, find by username, verify identity, people search, public-data background check, who is this caller. NOT FOR structured due-diligence or company/entity intelligence investigations, or general web research synthesis (use Research)."
5---
6 
7## Customization
8 
9**Before executing, check for user customizations at:**
10`~/.claude/LIFEOS/USER/CUSTOMIZATIONS/SKILLS/PrivateInvestigator/`
11 
12If this directory exists, load and apply any PREFERENCES.md, configurations, or resources found there. These override default behavior. If the directory does not exist, proceed with skill defaults.
13 
14 
15## 🚨 MANDATORY: Voice Notification (REQUIRED BEFORE ANY ACTION)
16 
17**You MUST send this notification BEFORE doing anything else when this skill is invoked.**
18 
191. **Send voice notification**:
20 ```bash
21 curl -s -X POST http://localhost:31337/notify \
22 -H "Content-Type: application/json" \
23 -d '{"message": "Running the WORKFLOWNAME workflow in the PrivateInvestigator skill to ACTION"}' \
24 > /dev/null 2>&1 &
25 ```
26 
272. **Output text notification**:
28 ```
29 Running the **WorkflowName** workflow in the **PrivateInvestigator** skill to ACTION...
30 ```
31 
32**This is not optional. Execute this curl command immediately upon skill invocation.**
33 
34# PrivateInvestigator - Ethical People Finding
35 
36## What It Does
37 
38Finds people and verifies identities using public data only. It covers people-search aggregators, social media, public records, and reverse lookups in parallel, then scores results by confidence (HIGH/MEDIUM/LOW/POSSIBLE) and trusts a match only when 3+ independent identifiers align.
39 
40## The Problem
41 
42Finding a real person from a name, a phone number, or an email is scattered across dozens of sources — people-search sites, county records, court portals, social platforms, reverse-lookup services — and no single one gives you the answer. Common names make it worse: search "John Smith" and you get thousands of people, most of them the wrong one. Run the searches one at a time and you either give up before you've covered enough sources or you act on a single weak match and contact the wrong person. This skill runs the sources in parallel and refuses to call a match real until several independent identifiers line up.
43 
44## How It Works
45 
46**Public data only.** No hacking, pretexting, or authentication bypass — every technique here is legal and ethical. The work runs as a parallel investigation across the source categories below; findings get cross-checked and confidence-scored before anything is reported. Choose the fan-out breadth the case needs — a common name across many states wants wide parallel coverage, a rare name in one city wants far less.
47 
48## Workflow Routing
49 
50| Workflow | Trigger | File |
51|----------|---------|------|
52| FindPerson | "find person", "locate", "search for [person]", "reconnect", "lost contact" — full parallel-agent investigation | `Workflows/FindPerson.md` |
53| SocialMediaSearch | "social media search" — cross-platform social media investigation | `Workflows/SocialMediaSearch.md` |
54| PublicRecordsSearch | "public records" — government and official records search | `Workflows/PublicRecordsSearch.md` |
55| ReverseLookup | "reverse lookup" — phone, email, image, username searches | `Workflows/ReverseLookup.md` |
56| VerifyIdentity | "verify identity" — confirm correct person match | `Workflows/VerifyIdentity.md` |
57 
58**When executing a workflow, output this notification:**
59```
60Running the **WorkflowName** workflow in the **PrivateInvestigator** skill to ACTION...
61```
62 
63## When to Activate
64 
65### Direct People-Finding
66- "find [person]", "locate [person]", "search for [person]"
67- "reconnect with [person]", "looking for lost contact"
68- "find an old friend", "locate a former coworker"
69 
70### Reverse Lookup
71- "reverse phone lookup", "who owns this email"
72- "reverse image search", "find person by username"
73 
74### Investigation
75- "background check" (public data only)
76- "what can you find about [person]"
77- "research [person]"
78 
79## Research Strategy
80 
81**Done = broad, independent coverage.** Every source category below is worked, and no key identifier (address, employer, DOB, family, social handle) rests on a single source. Run the categories in parallel — dispatch research agents concurrently in one message — and scale the fan-out to the case: a common name across many states justifies many parallel agents and spelling/location variants; a rare name in one city needs only a few. Independence is the point, not headcount: aggregators that resell the same database count as one source, so weight toward genuinely distinct origins (social the subject created, government records, unrelated aggregators).
82 
83## Core Capabilities
84 
85### 1. People Search Aggregators
86| Service | Type | Best For |
87|---------|------|----------|
88| TruePeopleSearch | Free | Best free option, fresh data |
89| FastPeopleSearch | Free | Basic lookups, no signup |
90| Spokeo | Freemium | Social media aggregation (120+ networks) |
91| BeenVerified | Paid | Comprehensive background data |
92 
93### 2. Social Media Investigation
94- **Facebook:** Google x-ray searches, mutual friends, groups
95- **LinkedIn:** Boolean search, alumni networks
96- **Instagram/Twitter/TikTok:** Username patterns, cross-platform correlation
97 
98### 3. Public Records
99- **Voter Registration:** Most states publicly available
100- **Property Records:** County assessor/recorder sites
101- **Court Records:** PACER (federal), state court portals, CourtListener
102- **Business Filings:** Secretary of State websites
103- **Professional Licenses:** State licensing boards
104 
105### 4. Reverse Lookup
106- **Phone:** CallerID, NumLookup, carrier lookup
107- **Email:** Epieos, Holehe, Hunter.io
108- **Image:** PimEyes, TinEye, Google/Yandex Images
109- **Username:** Sherlock, WhatsMyName, Namechk
110 
111### 5. Google Dorking
112```
113site:linkedin.com "John Smith" "Software Engineer"
114site:facebook.com "lives in" "Austin" "marketing"
115filetype:pdf resume "Jane Doe" "San Francisco"
116```
117 
118## Investigation Methodology
119 
120Anchor on whatever foundation identifiers the request gives — full name (and variations/maiden names), approximate age or DOB, last known location, context (school, workplace, relationship) — then pull from every source category until identifiers corroborate. Each discovered fact (phone, email, username, address, relative) is itself a new lead to run back through the sources, and every candidate gets a timeline-consistency and cross-source check before it earns a confidence score. The order is yours; the finish line is a match that survives the 3+-independent-identifier bar below.
121 
122## Confidence Scoring
123 
124| Level | Criteria | Action |
125|-------|----------|--------|
126| **HIGH** | 3+ unique identifiers match across independent sources | Safe to contact |
127| **MEDIUM** | 2 identifiers match, timeline consistent | Verify before contact |
128| **LOW** | Single source or name-only match | Needs more investigation |
129| **POSSIBLE** | Partial match, requires verification | Do not act without more data |
130 
131## Dealing with Common Names
132 
1331. **Add Specificity** - Include location, age, employer, school
1342. **Cross-Reference** - Match DOB + address patterns across sources
1353. **Family Connections** - Verify through known relatives
1364. **Timeline Analysis** - Does the life history make sense?
1375. **Multiple Identifiers** - Require 3+ matching data points
138 
139## Legal & Ethical Boundaries
140 
141### GREEN ZONE (Allowed)
142✅ Search public records (property, court, voter, business)
143✅ Access publicly posted social media content
144✅ Use people search aggregator sites
145✅ Perform reverse lookups on public data
146✅ Google dorking with public search operators
147 
148### RED ZONE (Never Cross)
149❌ Access data behind login walls without authorization
150❌ Bypass authentication or security measures
151❌ Use pretexting or impersonation
152❌ Access private databases (credit, financial, medical)
153❌ Stalk, harass, or intimidate subjects
154❌ Access PI-only databases without license
155 
156## When to STOP
157 
158- If the purpose shifts to harassment or stalking
159- If the subject has clearly opted out of contact
160- If investigation requires illegal methods
161- If you suspect the requestor has malicious intent
162 
163## Examples
164 
165**Example 1: Finding an Old College Friend**
166```
167User: "Help me find my college roommate from 2005, John Smith from Austin"
168→ Routes to FindPerson.md
169→ Fans out parallel research across the source categories
170→ Cross-references people search + LinkedIn alumni + property records
171→ Verifies identity through timeline analysis
172→ Reports findings with HIGH confidence
173```
174 
175**Example 2: Reverse Phone Lookup**
176```
177User: "Who called from 512-555-1234?"
178→ Routes to ReverseLookup.md
179→ Runs phone through CallerID, NumLookup
180→ Cross-references with people search aggregators
181→ Reports owner name, location, carrier
182```
183 
184**Example 3: Social Media Investigation**
185```
186User: "Find Jane Doe's social media, she's a marketing professional in Denver"
187→ Routes to SocialMediaSearch.md
188→ LinkedIn Boolean search + Google x-ray
189→ Username enumeration if handle discovered
190→ Reports all accounts with MEDIUM/HIGH confidence
191```
192 
193---
194 
195**Related Documentation:**
196- Complete workflow details in `Workflows/` directory
197- Integration with Research skill for parallel agent orchestration
198 
199## Gotchas
200 
201- **Ethical framework is mandatory.** Legitimate purposes only — reconnection, due diligence, safety. No stalking or harassment.
202- **Wide parallel fan-out can hit rate limits on public records APIs.** Stagger launches if services throttle.
203- **Verify findings across multiple sources.** Single-source results are unreliable.
204 
205## Execution Log
206 
207After completing any workflow, append a single JSONL entry:
208 
209```bash
210echo '{"ts":"'$(date -u +%Y-%m-%dT%H:%M:%SZ)'","skill":"PrivateInvestigator","workflow":"WORKFLOW_USED","input":"8_WORD_SUMMARY","status":"ok|error","duration_s":SECONDS}' >> ~/.claude/LIFEOS/MEMORY/SKILLS/execution.jsonl
211```
212 
213Replace `WORKFLOW_USED` with the workflow executed, `8_WORD_SUMMARY` with a brief input description, and `SECONDS` with approximate wall-clock time. Log `status: "error"` if the workflow failed.
214 

Discussion

Alternatives