What problem does it solve? External reconnaissance engagements often produce unstructured, uncorroborated findings with no consistent severity grading, confidence tracking, or reproducible evidence trail. This Skill provides a complete methodology for planning and executing authorized OSINT and attack-surface assessments, from seed discovery through client-ready reporting. ## Core Features & Use Cases - Five-Stage Recon Pipeline: Structured workflow covering seed discovery, asset expansion, enrichment, exposure analysis, and reporting, with time budgets for 1-hour to 1-week engagement profiles. - Asset Graph Discipline: 29 typed asset types, 23 typed edges, confidence levels (TENTATIVE/FIRM/CONFIRMED), and per-asset-type triage and upgrade rules. - Specialized Modules: Identity-fabric mapping (Entra/Okta/ADFS/M365), breach×identity correlation, WAF/CDN bypass and origin discovery, vulnerability prioritization (CVE/EPSS/KEV), phishing infrastructure planning, and bug bounty submission templates. - Use Case: During an authorized red-team engagement against acme.com, use the pipeline to enumerate subdomains, fingerprint the SSO tenant, correlate leaked credentials from breach corpora, and deliver a severity-graded findings report with an executive summary. ## Quick Start Ask the assistant to plan and execute an external reconnaissance engagement against an authorized target domain using the five-stage OSINT pipeline with a one-day time budget.