recon-and-methodology

Organize reconnaissance workflows for bug bounty engagements.

5|1|Updated Apr 20, 2026
One-click install
npx skills add https://github.com/Yliken/ai4 --skill recon-and-methodology-yliken
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: recon-and-methodology
Source: https://github.com/Yliken/ai4/tree/main/skills/recon-and-methodology
Command: npx skills add https://github.com/Yliken/ai4 --skill recon-and-methodology-yliken

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Reconnaissance and methodology playbook to map assets, discover endpoints, fingerprint technologies, and build a structured testing plan for a new target.

Core Features & Use Cases

  • Systematic asset discovery and tech fingerprinting across targets
  • Endpoint discovery and surface mapping to outline testing scope
  • Repeatable playbook for bug bounty engagements with clear staging
  • Use Case: Apply to initial reconnaissance, scope definition, and plan-driven pentesting

Quick Start

Provide a target and follow the hierarchy to map assets, identify tech, and outline a structured plan.

Frequently Asked Questions about recon-and-methodology

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I build a structured reconnaissance plan for a new bug bounty target?

Build a structured reconnaissance plan by mapping assets, discovering endpoints, and fingerprinting technologies to outline a clear testing scope. This systematic workflow ensures repeatable findings and defined escalation paths for new engagements.

What is the best way to map assets and discover endpoints during pentesting?

The best way to map assets and discover endpoints is applying a systematic reconnaissance playbook. This approach organizes initial target mapping and surface enumeration into defined stages, yielding comprehensive coverage for pentesting engagements.

How does tech fingerprinting fit into a bug bounty methodology?

Tech fingerprinting fits into bug bounty methodology by identifying target technologies during the initial reconnaissance phase. It maps the attack surface, allowing you to outline structured testing steps and define clear escalation paths for discovered vulnerabilities.

Can I use a systematic recon playbook for scope definition and plan-driven pentesting?

Yes, you can use a systematic recon playbook for scope definition and plan-driven pentesting. It organizes asset discovery and endpoint mapping into repeatable testing stages, satisfying requirements for structured processes and clear escalation paths.

When do I need a repeatable reconnaissance workflow for security testing?

You need a repeatable reconnaissance workflow when starting new bug bounty engagements or mapping unfamiliar targets. It provides a staged hierarchy for asset discovery and endpoint enumeration, ensuring consistent coverage and structured testing plans.