Claude Sleuth: A 56-Task Investigation Workflow for Claude AI

What Claude Sleuth Does
Claude Sleuth is a 6-phase, 56-task workflow designed for Claude AI that structures complex investigations. The workflow consists of: Operational Direction, Intelligence Collection, Collation & Entity Resolution, Chronological & Relational Processing, Hypothesis & Reasoning, and concludes with a Final Report. It provides templates for every step and reference files for each task, which are output by task_runner.py upon completion of each gate. The system works across all Claude platforms including mobile, not just CLI.
Core Architecture
The system maintains persistent investigation state across sessions via Cloudflare D1, storing entities, relationships, timelines, evidence, grades, and the Investigation Notebook. It includes 16-section Cognitive Surrogate Profiling from documentary evidence, advancing the profile whenever subject information is synthesized, plus a 12-technique reasoning framework with a diagnose function for impasses, competing framing, or stuck points.
Analytical Frameworks
- Admiralty 6x6: Grades source reliability (A–F) and credibility (1–6) independently before any claim enters the record
- ACH: Derives conclusions via the Inconsistency Principle — surviving hypotheses have the least evidence against them
- ICD 203: Maps every probabilistic statement to a 7-tier scale, prohibiting vague qualifiers
Output Conventions
- Timestamps: ISO 8601, normalized to UTC
- Entity records: POLE schema with mandatory source, date_observed, analyst_id, and confidence fields
- Network edges: source_node, target_node, relationship_type, evidence_ref; edges are directed (source → target)
- Evidence custody: SHA-256 hash, capture timestamp, analyst ID, storage location
- Probability language: ICD 203 7-tier scale
Script Reference
task_runner.py: Drives the 56-task pipeline (next,done,status,jump,peek,notebook,reset)template_builder.py: Assembles Markdown working documents fromtemplates/by phase, step, or task IDsource_grader.py: Admiralty 6x6 source reliability and credibility grading with action recommendationsentity_resolver.py: Fellegi-Sunter probabilistic record linkage; deterministic matching on unique identifierscorporate_intel.py: Aggregates company data from UK Companies House, SEC EDGAR, GLEIF LEI, and ICIJ Offshore Leaksdomain_intel.py: Domain reconnaissance via DNS, RDAP, crt.sh, Shodan InternetDB — zero authentication requiredusername_enum.py: Async username enumeration across social platforms using Maigret, Sherlock, or WhatsMyNamesanctions_screen.py: Fuzzy name matching against OFAC SDN, UK HMT, and other public sanctions listsevidence_preservation.py: Forensic web capture: screenshots, HTML, WARC, Wayback submission, SHA-256 chain of custodycontent_archiver.py: Async media download and cataloguing via yt-dlp, gallery-dl, and Playwright with manifest generationchronological_matrix.py: UTC-normalised timeline construction; gap detection, source conflict flagging, CSV exportnetwork_graph.py: Directed POLE relationship graph; in/out-degree, PageRank, community detection, HTML/GEXF exportgeolocation.py: EXIF GPS extraction, solar position/shadow analysis, historical weather correlation, reverse geocodingfinancial_analysis.py: SEC EDGAR financial anomaly detection: Benford's Law, YoY variance, Altman Z-Scorereport_generator.py: ICD 203-compliant briefings and findings memos via Jinja2 templates; optional WeasyPrint PDF export
Who It's For
This workflow is designed for developers and analysts using Claude AI for structured investigations, intelligence gathering, or complex research projects requiring standardized methodologies and persistent state management.
📖 Read the full source: r/ClaudeAI
👀 See Also

Swarm Leak Detector: Free Tool to Scan for Exposed API Keys in OpenClaw Configs
A developer released swarm-leak-detector, a zero-dependency MIT-licensed tool that scans for over 21 credential patterns (OpenAI, Anthropic, OpenRouter, Stripe, etc.) in plaintext JSON config files. Run it with npx swarm-leak-detector scan ~/.clawdbot/ to check for leaks in about 30 seconds.

Claude-kit: Configuration Management System for Claude Code Projects
Claude-kit is an open-source tool that manages .claude/ directory configurations across multiple projects. It auto-detects tech stacks, generates configs, audits security and quality, and syncs changes without overwriting customizations.

agentcontract v0.0.1: A Portable JSON Permission Layer for AI Coding Agents
agentcontract v0.0.1 introduces a portable JSON permission layer for AI agents, with a local browser UI for editing, validating, and dry-running tool calls.

RUNE Protocol: Save AI Session Memory Across Platforms
RUNE (Relational User Notation for Entities) is an open-source protocol that saves your AI relationship to an encrypted .rune file, solving the cold-start problem where AI assistants forget you between sessions. Created with Claude Opus 4.6, it works across Claude and GPT platforms.