recon-breweries

Probe brewery websites for exposed APIs and misconfigured e-commerce platforms.

3|1|Updated Jul 2, 2026
One-click install
npx skills add https://github.com/EntroVyx/hermes-agent-offsec --skill recon-breweries-entrovyx
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: recon-breweries
Source: https://github.com/EntroVyx/hermes-agent-offsec/tree/main/skills/offsec/redteam/recon-breweries
Command: npx skills add https://github.com/EntroVyx/hermes-agent-offsec --skill recon-breweries-entrovyx

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill automates the discovery of common misconfigurations and exposed endpoints in craft brewery, brewpub, and distillery websites, which often rely on insecure e-commerce and menu integrations.

Core Features & Use Cases

  • Platform Fingerprinting: Identifies CMS and POS systems like WooCommerce, Shopify, and Toast.
  • Vulnerability Discovery: Detects age-gate bypasses, exposed menu APIs, and unauthenticated e-commerce REST endpoints.
  • Use Case: Quickly audit a target brewery site to find exposed customer data in WooCommerce or discover hidden product catalogs in Shopify.

Quick Start

Use the recon-breweries skill to perform a full security audit on the target domain example.com.

Frequently Asked Questions about recon-breweries

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I find exposed APIs and e-commerce vulnerabilities on a Shopify site?

To find exposed APIs on Shopify sites, perform targeted reconnaissance using automated HTTP probing and header analysis. This process detects unauthenticated REST endpoints and hidden product catalogs by fingerprinting the platform and mapping its attack surface.

What is an age-gate bypass vulnerability in web security?

An age-gate bypass is a web security misconfiguration allowing users to circumvent age verification mechanisms. Targeted reconnaissance identifies these flaws on brewery and distillery websites by probing custom web stacks and analyzing HTTP headers.

Can I audit a WordPress WooCommerce store for unauthenticated endpoints?

Yes, you can audit WooCommerce stores for unauthenticated endpoints using sector-specific reconnaissance. Automated HTTP probing identifies exposed e-commerce REST APIs and extracts sensitive business logic data without requiring authentication.

What's the best way to test menu system vulnerabilities on custom web stacks?

The best way to test menu system vulnerabilities is running automated HTTP probing against custom web stacks. This reconnaissance identifies insecure POS integrations, detects exposed menu APIs, and maps the application attack surface.

Does this vulnerability assessment approach work for ecommerce platform fingerprinting?

Yes, this vulnerability assessment approach supports ecommerce platform fingerprinting. It identifies CMS and POS systems like WooCommerce, Shopify, and Toast through header analysis to map targeted attack surfaces.