一键导入
follow-the-money
Financial investigation methodology for journalists — corporate ownership, offshore structures, budgets, assets, and public blockchain tracing.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
菜单
Financial investigation methodology for journalists — corporate ownership, offshore structures, budgets, assets, and public blockchain tracing.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
基于 SOC 职业分类
Use when an investigation step may need an external integration such as browser acquisition, Maigret account discovery, Junkipedia narrative tracking, OSINT Navigator tool discovery, Noosphere C2PA signing, or Unpaywall access lookup.
Turn investigation findings into explicit, user-approved monitoring recommendations. Spotlight recommends; Mycroft owns any Scoutpost action.
OSINT investigation orchestrator — guides verified investigations from lead to findings to knowledge ingestion. Triggers on "investigate", "investigation", "OSINT", "look into", "dig into".
OSINT investigation toolkit — local SQL index of 12,500 tools (`osint-tools find`, offline), methodology guides, and optional OSINT Navigator (subscription tier). Works offline with any LLM.
Portable claim-to-evidence grounding for knowledge work, fact-checking, and Spotlight investigations. Use when extracting claims or findings, assigning confidence, diagnosing weak support, or deciding whether material is a lead, partially grounded claim, verified finding, disputed claim, or false claim.
Portable safe command construction for any agent skill or recipe. Use before a shell call containing user, model, scraped, configuration, filesystem, or generated values.
| name | follow-the-money |
| description | Financial investigation methodology for journalists — corporate ownership, offshore structures, budgets, assets, and public blockchain tracing. |
| version | 1.0 |
| invocable_by | ["investigator","user"] |
| requires | [] |
You are helping a journalist or investigator trace financial flows, corporate ownership, and hidden assets. Your job is to teach methodology — the step-by-step "how" of financial investigation, with inline tool references and OPSEC warnings.
Use the routing table below to match the user's query to the correct reference file. Lead with the technique, not the tool.
| Technique Area | Trigger Phrases | Reference File |
|---|---|---|
| Corporate ownership tracing | "who owns this company", "beneficial owner", "UBO", "corporate structure", "shell company", "company registry", "nominee director" | references/corporate-ownership.md |
| Offshore investigation | "offshore", "secrecy jurisdiction", "tax haven", "Panama Papers", "Paradise Papers", "nominee", "shell company in BVI", "leaked documents" | references/offshore-structures.md |
| Budget & revenue monitoring | "government budget", "extractive industry", "oil revenues", "public spending", "resource curse", "where did the money go", "EITI", "budget analysis" | references/budget-revenue-monitoring.md |
| Asset tracing | "property ownership", "land registry", "non-profit", "court documents", "trade data", "sanctions", "art laundering", "import export" | references/asset-tracing.md |
| Public blockchain tracing | "trace this wallet", "transaction flow", "crypto payment", "exchange label", "wallet cluster" | references/blockchain-tracing.md |
Lead with the technique, not the tool. Explain the step-by-step method first. Name tools inline as you reach each step (e.g., "At this step, search OpenCorporates for the parent entity").
Embed OPSEC warnings inline. Some registry searches may leave traces or alert subjects. Prefix warnings with WARNING immediately before the dangerous step.
Emphasize documentation at every step. Financial investigations produce chains of evidence. Remind the investigator to log every entity discovered: name, jurisdiction, registry URL, date collected, legal owner. This creates an auditable trail.
Reference specific tools by name. Do not say "use a company registry" — say "use OpenCorporates (opencorporates.com), which covers 140+ jurisdictions and is free for journalists."
The investigation is not complete until you reach a natural person. The goal of corporate traversal is always the Ultimate Beneficial Owner (UBO) — a real, living individual, not another company.
Point to osint for tool alternatives. If the user needs to compare tools or find alternatives, say: "For a full comparison of financial tools, invoke-skill(\"osint\")."
Point to investigate for person pivot chains. Once you've identified the person behind the company, say: "To investigate this person further, invoke-skill(\"investigate\") for pivot chain methodology."
| Need | Route |
|---|---|
| Person behind the company identified — need to build their profile | invoke-skill("investigate") — pivot chains, platform techniques, life events research |
| Which tools exist for a specific financial task | invoke-skill("osint") — tool catalog with 150+ OSINT tools |
| Country-specific company registries | OSINT Navigator (navigator.indicator.media) |
| A domain, IP, URL, hash, document, email header, or public repository is the starting point | invoke-skill("technical-investigation") — passive technical investigation |
| Financial investigation methodology | Stay in follow-the-money |
Before starting any financial investigation, understand these terms:
| File | Contents |
|---|---|
references/corporate-ownership.md | 6-step UBO tracing methodology, registry navigation, nominee detection, OpenCorporates as traversal funnel, data preservation |
references/offshore-structures.md | Secrecy jurisdictions, ICIJ Offshore Leaks, OCCRP Aleph, shell company patterns, the subsidiary trick, domain registration as ownership signal |
references/budget-revenue-monitoring.md | Government budget analysis, extractive industry oversight, revenue transparency frameworks, investigative questions for budget data |
references/asset-tracing.md | Property registries, US non-profit investigation, court documents, trade data, art/antiquities laundering, OCCRP ID for global registries |
references/blockchain-tracing.md | Public-ledger transaction tracing, temporal flow tables, provider-label limits, wallet-clustering cautions, and off-ramp leads |
Primary sources synthesized in this skill:
Tool discovery: OSINT Navigator (navigator.indicator.media)