What problem does it solve? When a target's visible application surface looks thin, this Skill turns publicly exposed artifacts—JavaScript bundles, source maps, archived URLs, support docs, API examples, and infrastructure breadcrumbs—into a structured map of hidden routes, roles, objects, and second-order pivots. ## Core Features & Use Cases - Artifact Classification: Prioritizes client-side assets, public operational artifacts, third-party relationship artifacts, and cloud/infrastructure breadcrumbs as intelligence sources. - Pivot Graph Construction: Converts each artifact into a graph linking bundles to routes, source maps to original filenames, archived URLs to deprecated endpoints, and support articles to hidden workflow states. - Confidence Scoring: Ranks leads by source quality, recency, cross-source repetition, and pivot value so small leaks that unlock new search spaces outrank generic endpoint lists. - Use Case: During a web application assessment where the homepage reveals little, use this Skill to mine the JS bundle, Wayback Machine snapshots, and help-center articles to enumerate hidden API routes, role names, and feature flags, then produce a confidence-ranked queue of manual tests. ## Quick Start Analyze the target's public JavaScript bundles, archived URLs, and support documentation to build an attack-surface map with second-order pivots and a ranked list of manual tests.