LogoAwesome Skills
  • Search
  • Category
  • Tag
  • Blog
LogoAwesome Skills
LogoAwesome Skills

Discover Open-Source Agent Skills for AI Coding Assistants

Product

  • Search
  • Category
  • Tag
  • Blog

Resources

  • Claude Skill Docs
  • Antigravity Skills Docs

Tools

  • Claude Code
  • OpenCode
  • Cursor
  • Codex
  • Antigravity

Company

  • Privacy Policy
  • Terms of Service
  • Sitemap

©2026 Awesome Skills. All rights reserved.

Privacy PolicyTerms
Back to Skills

recon-a-domain-passively

End-to-end passive reconnaissance for a domain, website or IP — builds an asset inventory covering registration, DNS, subdomains, infrastructure, tech stack, history and ownership without sending a single packet to the target. Use when asked to research or profile a domain or website, map what an organisation runs, or investigate a suspicious site without alerting its operator. Applies to vendor and third-party risk assessment, attack-surface review, M&A technical diligence, phishing and fraud-s

12stars1forksUpdated 8/13/2026
Security#security#osint#threat-intelligence#attack-surface#dns#reconnaissance

Security Assessment

Low Risk(88/100)

Detected risks:

Dual-Use Reconnaissance(The skill automates reconnaissance that profiles a target organization's internet-facing assets and ownership, which is inherently dual-use even though it is framed and gated for defensive attack-surface and third-party risk work., It maps subdomains, infrastructure, and owner attribution for a third party, information that could aid targeting if used outside an authorized engagement.)
Security Score88/100

About recon-a-domain-passively

Recon a Domain Passively is an OSINT workflow that turns a single domain, website, or IP into a defensible inventory of an organization's internet-facing estate and the owner behind it — without sending a single packet to the target. Its distinctive contribution is not new techniques but the order, the inventory discipline, and a stopping rule. It explicitly guards against two failure modes: enumerating for hours and producing an unattributed pile of hostnames, and quietly drifting from passive into active probing.

The workflow runs six ordered, cheapest-and-quietest-first stages as a loop: registration and DNS baseline, name-space expansion from archival sources like Certificate Transparency and passive DNS, resolution and inventory building, infrastructure and services from third-party scan platforms only, content/history/code/tech-stack assembly from archives and indexes, and owner attribution. Each stage has a written 'done when' criterion and feeds selectors back to earlier stages. It leans on companion skills (who-owns-this-domain, find-hidden-subdomains, find-exposed-servers, read-deleted-pages, google-like-a-spy, secrets-in-git-history, find-the-original-image) and a reference schema for the asset inventory. Step 1 requires writing down authorized scope, jurisdiction, and the passive boundary, and references a repository ETHICS.md; the skill also sets disable-model-invocation so it is not auto-triggered.

It targets security teams and analysts doing vendor and third-party risk assessment, attack-surface review, M&A technical diligence, phishing and fraud-site investigation, and pre-engagement scoping. This is dual-use reconnaissance tooling, but the framing is strictly passive, authorization-gated, and defensively oriented — it uses only third-party archival and scan data and forbids probing the target directly. The reconnaissance nature and the fact that it profiles third parties are the only notable considerations, and both are heavily mitigated by the scope and passive-boundary discipline built into the workflow.

FAQ

Why is it called 'passive'?

Because it builds its map entirely from third-party archival and scan sources — Certificate Transparency, passive DNS, scan platforms, web archives, and indexes — without sending any packets to the target, so the operator is not alerted.

Does it require authorization?

Yes. Step 1 requires writing down the subject, objective, out-of-bounds list, jurisdiction, and passive boundary, and references a repository ETHICS.md; it is also marked disable-model-invocation so it is not auto-triggered.

What does it actually produce?

A deduplicated, timestamped asset inventory covering registration, DNS, subdomains, resolved IPs and ASNs, infrastructure and services, tech stack, and owner attribution, each finding tied to the artifact it rests on.

When does it stop?

When a saturation-based stopping rule is met: two consecutive new sources yield no new assets, every name is resolved or classified with an owner and attribution grade, and naming-convention gaps are accounted for.

Could this be misused?

Reconnaissance is inherently dual-use, but the workflow is explicitly passive, scope-gated, and defensive (vendor risk, attack-surface review, diligence, phishing investigation), and it forbids any active probing of the target.

All Files

2 files
SKILL.md13.1 KB
View
reference/asset-inventory.md6.7 KB
View

Install recon-a-domain-passively

Download and extract the skill files to your .claude/skills/ directory.

Quick Setup:

  1. Copy the skill folder to .claude/skills/
  2. Claude will automatically detect and use the skill

Repository

useosint/osint-skills

Related Skills

tigris-security-access-control

3

rebuttal-writing

362

building-blocks

189

docs-search

189