What problem does it solve?
It helps you quickly identify what an external target exposes—domains, endpoints, technology fingerprints, and weak security signals—so you can focus your penetration testing where it matters most.
Core Features & Use Cases
- Passive recon: Finds relevant public information (vulnerabilities, subdomains, endpoints) without interacting directly with the target.
- Fingerprinting & service exposure: Checks server/app headers and common discovery paths like robots.txt, sitemap.xml, and well-known routes.
- Surface mapping & lightweight scanning: Uses browser inspection to uncover front-end/API relationships, then performs non-intrusive validation such as security-header checks.
Quick Start
Run the pentest-recon skill to generate a recon report for a target domain by collecting passive findings, fingerprinting exposed services, and summarizing discovered endpoints and security-header risks.