Skip to content
Security
Skill

/recon-for-sec

Entry P1 category router for reconnaissance and methodology. Use when mapping scope, drawing an attack surface from one application, discovering assets, fingerprinting technology, building endpoint inventory, and choosing the first high-value security testing path.

From plugin
hack-skills
2.2k103 skills
Install
$ npx -y skills add yaklang/hack-skills --skill recon-for-sec --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/recon-for-sec

Context preview

The summary Claude sees to decide when to auto-load this skill.

Entry P1 category router for reconnaissance and methodology. Use when mapping scope, drawing an attack surface from one application, discovering assets, fingerprinting technology, building endpoint inventory, and choosing the first high-value security testing path.

SKILL.md

recon-for-sec.SKILL.md
name: recon-for-sec
description: >-
  Entry P1 category router for reconnaissance and methodology. Use when mapping
  scope, drawing an attack surface from one application, discovering assets,
  fingerprinting technology, building endpoint inventory, and choosing the
  first high-value security testing path.

Recon and Methodology Router

This is the starting router for new targets and unknown attack surfaces.

When to Use

  • You just received a new target and do not yet know what to test first
  • You need to begin by drawing the surface from the application, then asset discovery, fingerprinting, and test-route planning
  • You want to build follow-up testing on structured methodology instead of random payload enumeration

Skill Map

  • [Attack Surface Mapping](../attack-surface-mapping/SKILL.md) — from one URL / one app, draw hosts, APIs, keys, and the object graph
  • [Recon and Methodology](../recon-and-methodology/SKILL.md)
  • [Insecure Source Code Management](../insecure-source-code-management/SKILL.md) — .git/.svn/.hg exposure detection
  • [Dependency Confusion](../dependency-confusion/SKILL.md) — Supply chain reconnaissance for internal package names

Recommended Flow

1. Confirm in-scope assets and target type 2. Draw the surface from the application: [attack-surface-mapping](../attack-surface-mapping/SKILL.md) 3. Route the inventory to [api-sec](../api-sec/SKILL.md), [auth-sec](../auth-sec/SKILL.md), [injection-checking](../injection-checking/SKILL.md), or [business-logic-vuln](../business-logic-vuln/SKILL.md)

Read more
Ships withhack-skills

Master Entry → Category Entries → Deep Topic Skills One master entry, six category entries, and 102 deep topic skills across 14 security domains.

Get the whole plugin

Other skills on hack-skills.