Runs token-efficient authorized OSINT and exposure reviews for Cursor and Codex. Builds compact sourced intel cards from public information the user is allowed to collect. Use when the user asks for OSINT, own-org attack surface, public leak checks, brand impersonation review, or a threat-intel summary. Do not use for stalking, doxxing, social engineering, credential stuffing, scraping login walls, or accessing non-public systems.