recon-for-sec
Entry P1 category router for reconnaissance and methodology. Use when mapping scope, discovering assets, fingerprinting technology, building endpoint inventory, and choosing the first high-value security testing path.
Security Assessment
About recon-for-sec
A starting-point router for security reconnaissance and methodology, meant to be loaded first when facing a new target or an unknown attack surface. Rather than jumping straight into payloads, it frames the early phase of an assessment around structured discovery: confirming in-scope assets and target type, then performing asset discovery, port and service identification, technology fingerprinting, and endpoint inventory before any exploitation is attempted.
It is designed for the moment when a tester has just received a target and does not yet know what to test first, and wants to build follow-up testing on a documented methodology instead of random enumeration. As a router, its main job is to point to the right next skill: it maps to a fuller Recon and Methodology skill, plus focused reconnaissance skills for insecure source-code management (detecting exposed .git, .svn, and .hg directories) and dependency confusion (supply-chain reconnaissance for internal package names).
The recommended flow is to first confirm scope and target type, then collect assets, services, technologies, and endpoints, and finally route based on findings into downstream testing skills for API security, authentication, injection checking, or business-logic vulnerabilities. Because it is intentionally lightweight, it works as an index and decision aid at the top of an engagement rather than a deep technical playbook, ensuring reconnaissance is completed and organized before deeper category-specific testing begins.
FAQ
When should I load this skill?
At the start of an engagement, when you have just received a new target or unknown attack surface and do not yet know what to test first.
What should I do before running exploits?
Confirm in-scope assets and target type, then perform asset discovery, port/service identification, technology fingerprinting, and endpoint collection.
What does it route to after recon?
Based on findings it routes to downstream skills such as api-sec, auth-sec, injection-checking, or business-logic-vuln.
Does it cover source-code exposure or supply-chain checks?
Yes; its skill map links to Insecure Source Code Management for .git/.svn/.hg exposure and Dependency Confusion for internal package-name reconnaissance.
Is this a deep technical playbook?
No; it is a lightweight category router that organizes methodology and points to more detailed skills rather than providing exploitation techniques itself.
Install recon-for-sec
Quick Setup:
- Copy the skill folder to
.claude/skills/ - Claude will automatically detect and use the skill
Repository
yaklang/hack-skills