recon-and-methodology

Map attack surfaces and build structured web recon plans for authorized targets.

11|4|Updated Jun 7, 2026
One-click install
npx skills add https://github.com/sayseven7/frameseven --skill recon-and-methodology-sayseven7
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: recon-and-methodology
Source: https://github.com/sayseven7/frameseven/tree/main/internal/mcp/skills/recon-and-methodology
Command: npx skills add https://github.com/sayseven7/frameseven --skill recon-and-methodology-sayseven7

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill removes the guesswork from web security recon by turning a new target into a structured, prioritized testing plan that highlights where to look first.

Core Features & Use Cases

  • Asset discovery and attack-surface mapping: Identify subdomains, services, and exposed web paths before active testing.
  • Fingerprinting and endpoint finding: Infer technologies, discover hidden routes, and surface likely API and admin entry points.
  • Bug bounty workflow support: Organize recon into a repeatable sequence for authorized security testing, from broad enumeration to focused vulnerability checks.
  • Use Case: A researcher can use this Skill to move from a single domain name to a complete recon checklist covering hosts, ports, technologies, and high-value attack paths.

Quick Start

Use this skill to analyze an authorized target and produce a step-by-step reconnaissance and testing plan.

Frequently Asked Questions about recon-and-methodology

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I map an attack surface from a single domain for bug bounty reconnaissance?

Attack surface mapping starts with broad subdomain enumeration, technology fingerprinting, and endpoint discovery to identify exposed hosts, services, and web paths. This Skill transforms a single authorized domain into a structured, prioritized testing plan that highlights high-value entry points for systematic vulnerability triage.

What is the best way to organize web recon and vulnerability triage workflows?

Organizing web reconnaissance requires a repeatable sequence moving from broad asset discovery to focused vulnerability checks. This Skill structures authorized security testing into a step-by-step plan that systematically covers hosts, ports, technologies, and likely API or admin paths before active testing begins.

How does technology fingerprinting and endpoint discovery work during penetration testing?

Technology fingerprinting infers software frameworks and services running on a target, while endpoint discovery surfaces hidden routes and API entry points. This Skill guides tool-driven reconnaissance to expose these web paths and technologies, building a structured checklist for authorized penetration testing workflows.

Can I use this reconnaissance methodology for authorized subdomain enumeration and automated scanning?

Yes, this Skill is designed for authorized security testing, supporting subdomain enumeration, technology fingerprinting, and automated scanning guidance. It maps exposed assets and services into a structured web reconnaissance plan, ensuring systematic coverage of authorized targets during bug bounty workflows.

Do I need prior recon results to build a testing plan for exposed web paths?

No prior reconnaissance results are required. This Skill takes a new authorized target and removes the guesswork by generating a complete recon checklist covering hosts, ports, technologies, and high-value attack paths, turning a blank starting point into a prioritized testing plan.

When should I use a structured recon and testing plan instead of ad-hoc vulnerability scanning?

A structured recon and testing plan is necessary when you need systematic coverage of assets, services, and web paths rather than random checks. Use this Skill to move from broad enumeration to focused vulnerability triage, ensuring repeatable sequences for authorized bug bounty and penetration testing.