What problem does it solve?
This Skill transforms external reconnaissance observations into consistently scored, severity-ranked, evidence-backed findings while keeping analysis within authorized engagement, scope, and evidence-preservation controls.
Core Features & Use Cases
- Endpoint Interest Scoring: Assigns 0–100 scores to API endpoints using signals such as unauthenticated writes, GraphQL introspection, CORS behavior, sensitive paths, and schema leakage.
- Severity and Attack-Path Analysis: Applies decision matrices, sector-specific overrides, and attack-path hint templates to prioritize findings and guide safe next-step workflows.
- Mobile and Evidence Workflows: Evaluates mobile app ownership confidence, preserves artifact metadata, coordinates outputs through sidecar JSON, and supports vulnerability prioritization and reporting.
- Use Case: Analyze an authorized API inventory, identify high-interest endpoints, classify their severity, attach relevant attack-path hints, and prepare findings for client deliverables.
Quick Start
Ask the skill to score the supplied authorized reconnaissance findings, apply sector-specific severity rules, generate attack-path hints, and produce report-ready output.