recon-for-sec
yaklang/hack-skills
Entry-point router for security reconnaissance, attack surface mapping, and methodology planning.
What is recon-for-sec?
A starting skill for new security testing targets that helps you map scope, discover assets, fingerprint technology, and plan your first high-value testing path. Use this when you have a new target and need to systematically understand its attack surface before diving into specific vulnerability testing.
- Routes reconnaissance tasks to specialized skills (attack surface mapping, asset discovery, source code exposure detection, supply chain reconnaissance)
- Helps confirm in-scope assets and identify target type
- Draws application surface to discover hosts, APIs, keys, and object relationships
- Provides structured methodology instead of random payload enumeration
- Connects reconnaissance findings to follow-up testing skills (API security, authentication, injection, business logic)
How to install recon-for-sec
npx skills add https://github.com/yaklang/hack-skills --skill recon-for-secHow to use recon-for-sec
- 1.Confirm which assets are in-scope and identify the target type (web app, API, mobile backend, etc.)
- 2.Use attack-surface-mapping skill to draw the application surface and discover hosts, APIs, and keys
- 3.Review discovered inventory and categorize by asset type
- 4.Route findings to specialized skills: api-sec for APIs, auth-sec for authentication, injection-checking for input handling, or business-logic-vuln for workflow issues
- 5.Check for insecure source code management exposure and dependency confusion risks
Use cases
- Starting security assessment on a new web application or target
- Building endpoint inventory and technology fingerprinting for a company
- Discovering exposed source control repositories (.git, .svn, .hg)
- Identifying internal package names for supply chain attack reconnaissance
- Planning which specialized security testing skill to apply next based on discovered assets
- Security researchers and penetration testers
- Bug bounty hunters starting on new targets
- Security engineers planning application assessments
- DevSecOps teams mapping their own attack surfaces
recon-for-sec FAQ
Use this router first when you have a new target or unknown attack surface. It ensures you map scope and build a structured testing plan rather than guessing where vulnerabilities might be.
This is a high-level entry point that helps you decide which specialized reconnaissance skill to use next. The individual skills (attack-surface-mapping, recon-and-methodology, etc.) perform the actual detailed work.
You can, but you risk missing assets, testing out-of-scope targets, or wasting time on low-value areas. This router helps prioritize your testing effort.
A structured inventory of discovered assets (hosts, APIs, endpoints, technologies), confirmed in-scope boundaries, and a recommended testing path based on what you found.
Full instructions (SKILL.md)
Source of truth, from yaklang/hack-skills.
name: recon-for-sec description: >- Entry P1 category router for reconnaissance and methodology. Use when mapping scope, drawing an attack surface from one application, discovering assets, fingerprinting technology, building endpoint inventory, and choosing the first high-value security testing path.
Recon and Methodology Router
This is the starting router for new targets and unknown attack surfaces.
When to Use
- You just received a new target and do not yet know what to test first
- You need to begin by drawing the surface from the application, then asset discovery, fingerprinting, and test-route planning
- You want to build follow-up testing on structured methodology instead of random payload enumeration
Skill Map
- Attack Surface Mapping — from one URL / one app, draw hosts, APIs, keys, and the object graph
- Recon and Methodology
- Insecure Source Code Management — .git/.svn/.hg exposure detection
- Dependency Confusion — Supply chain reconnaissance for internal package names
Recommended Flow
- Confirm in-scope assets and target type
- Draw the surface from the application: attack-surface-mapping
- Route the inventory to api-sec, auth-sec, injection-checking, or business-logic-vuln
Related skills
More from yaklang/hack-skills and the wider catalog.

request-smuggling
HTTP request smuggling and desynchronization testing for proxy/origin framing disagreements.

reverse-shell-techniques
Reverse shell techniques playbook for establishing remote shells across Linux, Windows, and web platforms.

rsa-attack-techniques
Exploit weak RSA keys and parameters via factorization, small exponents, lattice attacks, and oracle techniques.

saml-sso-assertion-attacks
Test SAML SSO assertion signature validation, binding, and trust boundary flaws in enterprise authentication.

sandbox-escape-techniques
Expert sandbox escape techniques across Python, Lua, seccomp, chroot, Docker, browser, and namespace contexts.

smart-contract-vulnerabilities
Expert audit playbook for Solidity/EVM smart contract vulnerabilities: reentrancy, overflow, access control, delegatecall, MEV, and signature replay.