What problem does it solve?
Manual web application reconnaissance is tedious, inconsistent, and often misses critical endpoints or access control gaps. This Skill automates the entire attack surface discovery pipeline, replacing ad-hoc manual probing with a structured 18-phase workflow that ensures comprehensive coverage and traceable findings.
Core Features & Use Cases
- 18-Phase Autonomous Pipeline: Automates accessibility checks, crawling, fuzzing, parameter classification, flow mapping, and report generation without manual intervention.
- Multi-Role Access Testing: Profiles authenticated sessions and classifies responses across roles to surface broken access controls and IDOR-shaped anomalies.
- Quality Assurance Gates: Includes deterministic per-phase gates, a Quality Reviewer subagent, and a zero-context Final Judge to validate completeness and honesty before delivery.
- Use Case: A security engineer provides a target URL and optional credentials; the Skill discovers all reachable endpoints, identifies secrets in JavaScript bundles, maps user journeys, and produces a structured reconnaissance report with every finding traceable to its discovery source.
Quick Start
Use the attack-surface-discovery skill to autonomously map the attack surface of the provided web application target and generate a comprehensive reconnaissance report.