Check your breach exposure: what leaked about you
Check breach exposure for an email, username, phone or name — and interpret what the records really mean
- What
- Check breach exposure for an email, username, phone or name — and interpret what the records really mean
- Cost
- Free
- Needs
- none for the guidance itself; a Have I Been Pwned account/API key for programmatic or domain-wide checks; DeHashed/IntelX/Snusbase are paid commercial services if you need record-level search. Authorized use only — read the skill's legal and handling notes first.
- Install
- Copy the installer prompt below into your Muse — your agent does the rest.
Curated by Skill Harbor — ⚠️ **Security warning / Avertissement de sécurité — AUTHORIZED USE ONLY / USAGE AUTORISÉ UNIQUEMENT**: @useosint's guide to checking and interpreting data-breach exposure for an email, username, phone or name — which source to reach for (Have I Been Pwned, the Pwned Passwords k-anonymity range API, DeHashed, IntelX, Snusbase), what a breach record really contains and why the metadata (which service, registration date, username, signup IP) matters more than the credentials, the k-anonymity trick that lets you check a password you legitimately hold without disclosing it, service enumeration as the real pivot, combolist contamination and other traps (recycled breaches, breach date vs leak date, scrape-vs-breach confusion), confidence grading (confirmed / probable / unconfirmed / rejected), a worked self-audit example, and GDPR handling notes. Kept by editorial choice as a borderline case: the skill itself frames authorized use only and states a rule with no exceptions — never use a leaked credential to authenticate to anything, not even to "confirm" an account exists. Defensive/legitimate use only (incident response, account-takeover triage, personal privacy audits, authorized assessments). Honest caveats: breach-data handling is regulated (GDPR etc.) and some jurisdictions restrict possession — read the skill's legal notes before any use; MIT-licensed. Skill Harbor never reviews the code, review it yourself before use. Discovered via skills.sh.
Version:
Install
Prerequisites: none for the guidance itself; a Have I Been Pwned account/API key for programmatic or domain-wide checks; DeHashed/IntelX/Snusbase are paid commercial services if you need record-level search. Authorized use only — read the skill's legal and handling notes first. Install "Check your breach exposure: what leaked about you" for me. It teaches how to check breach exposure for an email, username, phone or name and interpret the records: source selection (HIBP, Pwned Passwords range API, commercial services), record field interpretation, service enumeration, confidence grading, and legal handling notes — by @useosint, MIT-licensed. Repository: https://github.com/useosint/skills/blob/main/skills/what-leaked-about-you/SKILL.md 1. Fetch the SKILL.md file (and any helper files) from the repository path into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md and scripts for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code, credentials only via the secure vault, allowed hosts declared in the SKILL.md. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md and its helper files into the agent's skills directory, in a folder named "what-leaked-about-you". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. read the legal/handling notes; never use a leaked credential to authenticate anywhere). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. If anything looks off, stop and ask me.
Questions
How do I install a build?
Every product page includes a copy-paste install prompt. Paste it into your Muse and it sets the build up for you — no manual configuration.
Where does my money go?
Straight to the seller. Skill Harbor never processes payments: checkout happens on the seller’s own page, usually Stripe.
What does the ✓ next to a creator’s name mean?
It means we confirmed the identity of the person behind the listing. It says nothing about the code itself — always check a build before installing it.