PluginBench
Skill
Review
Audit score 70

recon-for-sec

yaklang/hack-skills

Entry-point router for security reconnaissance, attack surface mapping, and methodology planning.

What is recon-for-sec?

A starting skill for new security testing targets that helps you map scope, discover assets, fingerprint technology, and plan your first high-value testing path. Use this when you have a new target and need to systematically understand its attack surface before diving into specific vulnerability testing.

  • Routes reconnaissance tasks to specialized skills (attack surface mapping, asset discovery, source code exposure detection, supply chain reconnaissance)
  • Helps confirm in-scope assets and identify target type
  • Draws application surface to discover hosts, APIs, keys, and object relationships
  • Provides structured methodology instead of random payload enumeration
  • Connects reconnaissance findings to follow-up testing skills (API security, authentication, injection, business logic)

How to install recon-for-sec

npx skills add https://github.com/yaklang/hack-skills --skill recon-for-sec
Claude Code
Cursor
Windsurf
Cline

How to use recon-for-sec

  1. 1.Confirm which assets are in-scope and identify the target type (web app, API, mobile backend, etc.)
  2. 2.Use attack-surface-mapping skill to draw the application surface and discover hosts, APIs, and keys
  3. 3.Review discovered inventory and categorize by asset type
  4. 4.Route findings to specialized skills: api-sec for APIs, auth-sec for authentication, injection-checking for input handling, or business-logic-vuln for workflow issues
  5. 5.Check for insecure source code management exposure and dependency confusion risks

Use cases

Good for
  • Starting security assessment on a new web application or target
  • Building endpoint inventory and technology fingerprinting for a company
  • Discovering exposed source control repositories (.git, .svn, .hg)
  • Identifying internal package names for supply chain attack reconnaissance
  • Planning which specialized security testing skill to apply next based on discovered assets
Who it's for
  • Security researchers and penetration testers
  • Bug bounty hunters starting on new targets
  • Security engineers planning application assessments
  • DevSecOps teams mapping their own attack surfaces

recon-for-sec FAQ

When should I use this skill versus jumping straight to a specific vulnerability test?

Use this router first when you have a new target or unknown attack surface. It ensures you map scope and build a structured testing plan rather than guessing where vulnerabilities might be.

What's the difference between this router and the individual reconnaissance skills?

This is a high-level entry point that helps you decide which specialized reconnaissance skill to use next. The individual skills (attack-surface-mapping, recon-and-methodology, etc.) perform the actual detailed work.

Can I skip this and go directly to testing?

You can, but you risk missing assets, testing out-of-scope targets, or wasting time on low-value areas. This router helps prioritize your testing effort.

What output should I expect from using this skill?

A structured inventory of discovered assets (hosts, APIs, endpoints, technologies), confirmed in-scope boundaries, and a recommended testing path based on what you found.

Full instructions (SKILL.md)

Source of truth, from yaklang/hack-skills.


name: recon-for-sec description: >- Entry P1 category router for reconnaissance and methodology. Use when mapping scope, drawing an attack surface from one application, discovering assets, fingerprinting technology, building endpoint inventory, and choosing the first high-value security testing path.

Recon and Methodology Router

This is the starting router for new targets and unknown attack surfaces.

When to Use

  • You just received a new target and do not yet know what to test first
  • You need to begin by drawing the surface from the application, then asset discovery, fingerprinting, and test-route planning
  • You want to build follow-up testing on structured methodology instead of random payload enumeration

Skill Map

  • Attack Surface Mapping — from one URL / one app, draw hosts, APIs, keys, and the object graph
  • Recon and Methodology
  • Insecure Source Code Management — .git/.svn/.hg exposure detection
  • Dependency Confusion — Supply chain reconnaissance for internal package names

Recommended Flow

  1. Confirm in-scope assets and target type
  2. Draw the surface from the application: attack-surface-mapping
  3. Route the inventory to api-sec, auth-sec, injection-checking, or business-logic-vuln