recon-bakeries

Probe bakery e-commerce sites for API misconfigurations and data leakage.

3|1|Updated Jul 2, 2026
One-click install
npx skills add https://github.com/EntroVyx/hermes-agent-offsec --skill recon-bakeries-entrovyx
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: recon-bakeries
Source: https://github.com/EntroVyx/hermes-agent-offsec/tree/main/skills/offsec/redteam/recon-bakeries
Command: npx skills add https://github.com/EntroVyx/hermes-agent-offsec --skill recon-bakeries-entrovyx

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill addresses the lack of sector-specific reconnaissance for small business e-commerce sites, such as bakeries and pastry shops, which often suffer from misconfigured APIs and exposed order data.

Core Features & Use Cases

  • Platform Fingerprinting: Automatically identifies CMS and e-commerce platforms like WooCommerce, Shopify, and Toast POS.
  • API & Form Auditing: Probes for unauthenticated access to WooCommerce REST endpoints and tests custom order forms for injection vulnerabilities.
  • Data Leakage Detection: Scans for exposed store locator data, manager contact information, and coupon code enumeration opportunities.

Quick Start

Use the recon-bakeries skill to perform a full security assessment on the target domain example-bakery.com.

Frequently Asked Questions about recon-bakeries

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I find unauthenticated WooCommerce REST endpoints on an e-commerce site?

To find unauthenticated WooCommerce REST endpoints, perform sector-specific reconnaissance using automated probes that scan the target domain for API misconfigurations and exposed store data. This process identifies unauthenticated access points and sensitive information leakage.

What is e-commerce reconnaissance for bakery and pastry shop websites?

E-commerce reconnaissance for bakery websites is the process of fingerprinting platforms like WooCommerce and Shopify to uncover security issues. It targets custom order form implementations to detect API misconfigurations, data leakage, and injection vulnerabilities.

Can I enumerate coupon codes and detect data leakage on Shopify sites?

Yes, you can enumerate coupon codes and detect data leakage on Shopify sites by executing targeted automated probes. These scans identify sensitive information exposure in store locators and uncover manager contact information.

Does this reconnaissance approach work with custom order forms and Toast POS platforms?

Yes, this reconnaissance approach works with custom order forms and Toast POS platforms by automatically fingerprinting the CMS. It tests custom forms for injection vulnerabilities and identifies e-commerce platform implementations.

What are the limitations of automated vulnerability probes for small business e-commerce sites?

Automated vulnerability probes for small business e-commerce sites are limited to detecting specific misconfigurations like unauthenticated REST endpoints and coupon enumeration. They focus on platform fingerprinting and data leakage rather than deep manual penetration testing.