recon-cafes

Probe coffee shop websites for exposed POS APIs and IDOR vulnerabilities.

3|1|Updated Jul 2, 2026
One-click install
npx skills add https://github.com/EntroVyx/hermes-agent-offsec --skill recon-cafes-entrovyx
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: recon-cafes
Source: https://github.com/EntroVyx/hermes-agent-offsec/tree/main/skills/offsec/redteam/recon-cafes
Command: npx skills add https://github.com/EntroVyx/hermes-agent-offsec --skill recon-cafes-entrovyx

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill streamlines the reconnaissance process for coffee shops, cafes, and tea houses by identifying sector-specific vulnerabilities like exposed POS API keys, loyalty program IDORs, and misconfigured store locators.

Core Features & Use Cases

  • Platform Fingerprinting: Automatically detects common platforms like Toast POS, Square Online, and Clover.
  • Vulnerability Probing: Targets high-risk endpoints including loyalty rewards, gift card balances, and online ordering APIs.
  • Use Case: Quickly identify if a cafe chain's online ordering system or loyalty program is susceptible to IDOR or API key exposure by scanning their public-facing web infrastructure.

Quick Start

Use the recon-cafes skill to perform a full reconnaissance scan on the target domain example-cafe.com.

Frequently Asked Questions about recon-cafes

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I find exposed POS API keys and IDOR vulnerabilities on cafe websites?

You can identify cafe vulnerabilities by probing frontend assets and high-risk endpoints such as loyalty rewards, gift card balances, and online ordering APIs to uncover exposed POS API keys, IDORs, and data leakage.

What is the best way to scan a coffee shop's online ordering system for security misconfigurations?

Targeted reconnaissance for cafe web assets automatically fingerprints common platforms like Toast POS, Square Online, and Clover, then probes their exposed endpoints to identify security misconfigurations and data leakage.

Do I need standard web reconnaissance tools to probe Toast POS and Square Online endpoints?

Standard web reconnaissance tools are required to probe endpoints and analyze frontend assets for security misconfigurations on platforms like Toast POS and Square Online.

Can I detect misconfigured store locators and loyalty program vulnerabilities on tea house websites?

This skill performs sector-specific reconnaissance on coffee shops, cafes, and tea houses to identify vulnerabilities including misconfigured store locators, loyalty program IDORs, and exposed POS integrations.

What types of data leakage can be uncovered when fingerprinting Clover and Square Online platforms?

Fingerprinting platforms like Clover and Square Online helps uncover data leakage including exposed API keys, loyalty program IDORs, and misconfigured store locators by probing high-risk endpoints.

Why are loyalty rewards and gift card balance endpoints considered high-risk for cafe web assets?

These endpoints are high-risk because reconnaissance targets them to uncover IDORs, exposed API keys, and data leakage in POS integrations on cafe web assets.