recon-carpet-cleaning

Identifies exposed data and insecure configurations in WordPress-based service sites.

3|1|Updated Jul 2, 2026
One-click install
npx skills add https://github.com/EntroVyx/hermes-agent-offsec --skill recon-carpet-cleaning-entrovyx
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: recon-carpet-cleaning
Source: https://github.com/EntroVyx/hermes-agent-offsec/tree/main/skills/offsec/recon-carpet-cleaning
Command: npx skills add https://github.com/EntroVyx/hermes-agent-offsec --skill recon-carpet-cleaning-entrovyx

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill addresses the inefficiency of manual reconnaissance on small-to-medium business (SMB) websites by automating the discovery of common vulnerabilities found in standardized agency-built service sites.

Core Features & Use Cases

  • Sector-Specific Recon: Identifies common patterns in carpet cleaning and water damage restoration sites, such as emergency booking forms and photo galleries.
  • Vulnerability Identification: Detects exposed debug logs, PII in uploads, and insecure WordPress plugin configurations.
  • Use Case: Quickly audit a list of local service provider domains to identify exposed customer data in debug logs or insecurely configured gallery plugins.

Quick Start

Run the recon-carpet-cleaning skill against the target domain list provided in carpet-targets.txt to identify potential WordPress vulnerabilities and exposed PII.

Frequently Asked Questions about recon-carpet-cleaning

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I scan WordPress sites for exposed debug logs and PII?

To scan WordPress sites for exposed debug logs and PII, you automate sector-specific reconnaissance targeting SMB service websites to identify common security misconfigurations like exposed customer data in debug logs or insecurely configured gallery plugins.

What is the best way to automate reconnaissance on small business service websites?

Automating reconnaissance on small business service websites involves scanning sector-specific targets like carpet cleaning sites to identify common patterns such as emergency booking forms and insecure WordPress plugin configurations.

Do I need Linux command-line utilities to perform WordPress vulnerability scanning?

Yes, performing WordPress vulnerability scanning requires standard Linux command-line utilities including curl, grep, and jq to execute domain discovery and endpoint analysis against target SMB service provider domains.

Can I audit a list of local service provider domains for security misconfigurations?

Yes, you can audit a list of local service provider domains for security misconfigurations by running automated reconnaissance against a provided target list to quickly identify exposed customer data and vulnerable plugin endpoints.

What vulnerabilities are commonly found in carpet cleaning business websites?

Vulnerabilities commonly found in carpet cleaning business websites include exposed debug logs, PII in uploads, and insecure WordPress plugin configurations. These security misconfigurations frequently result from standardized agency-built service site deployments.