What problem does it solve?
Coffee shop, cafe, and tea house websites frequently have unpatched vulnerabilities in their online ordering systems, loyalty programs, and third-party point-of-sale integrations that attackers can exploit to steal payment data, manipulate rewards, or access customer information, and most generic recon tools do not account for the unique tech stacks and common misconfigurations of these small food service businesses.
Core Features & Use Cases
- Sector-Specific Platform Fingerprinting: Automatically identifies common cafe tech stacks including Toast POS, Square Online, ChowNow, Olo, and Clover to prioritize recon efforts on high-risk integrations.
- Vulnerability Surface Mapping: Probes for exposed online ordering APIs, loyalty/rewards endpoints, store locator data leaks, and exposed POS API keys hidden in frontend JavaScript bundles.
- Common Attack Path Validation: Tests for prevalent cafe-specific vulnerabilities including menu item IDOR, loyalty points manipulation, unrestricted Google Maps API keys, and gift card balance enumeration.
- Use Case: A pentester assessing a local coffee chain can use this skill to quickly locate exposed Toast API keys in the site's JS code and test for loyalty points manipulation without building custom recon scripts from scratch.
Quick Start
Use the recon-cafes skill to perform a full sector-specific recon of a target coffee shop website, identify its point-of-sale platform, probe for exposed ordering and loyalty endpoints, and test for common cafe-specific vulnerabilities like API key exposure and points manipulation.