What problem does it solve? Security professionals running authorized external red-team engagements, bug bounty recon, or attack-surface assessments often lack a consistent methodology for scoping, evidence handling, confidence grading, and reporting. This Skill provides a structured operational framework that turns ad-hoc reconnaissance into a repeatable, defensible workflow. ## Core Features & Use Cases - Five-Stage Recon Pipeline: Seed discovery, asset expansion, enrichment, exposure analysis, and reporting, with priority ordering and time budgets for 1-hour to 1-week engagement profiles. - Asset Graph & Severity Discipline: 29 typed asset types, per-type triage rules, a three-tier confidence model (TENTATIVE/FIRM/CONFIRMED), and a CRITICAL-to-INFO severity rubric with escalation rules. - OpSec & Detection Awareness: Detectability tagging for probes, validator discipline for found credentials, and a back-off ladder when WAF blocks or rate limits appear. - Deliverable Templates: Bug bounty submission formats (HackerOne, Bugcrowd, Intigriti), executive summaries, risk translation tables, and reproduction packages. - Use Case: During an authorized bug bounty engagement, use the pipeline to enumerate subdomains, correlate breach data with the target's SSO tenant to produce an SSO_EXPOSURE finding, then generate a client-ready report with evidence hashes and remediation steps. ## Quick Start Ask the assistant to plan an external recon engagement against a domain you are authorized to test, starting with seed discovery and a scoped time budget.