recon-carwashes

Automate reconnaissance of car wash websites for exposed PII and vulnerable plugins.

3|1|Updated Jul 2, 2026
One-click install
npx skills add https://github.com/EntroVyx/hermes-agent-offsec --skill recon-carwashes-entrovyx
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: recon-carwashes
Source: https://github.com/EntroVyx/hermes-agent-offsec/tree/main/skills/offsec/redteam/recon-carwashes
Command: npx skills add https://github.com/EntroVyx/hermes-agent-offsec --skill recon-carwashes-entrovyx

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill automates the identification of security vulnerabilities specific to the car wash and auto detailing industry, which often relies on vulnerable WordPress plugins and misconfigured shared hosting environments.

Core Features & Use Cases

  • Sector-Specific Recon: Identifies subdomains and portals associated with common car wash management platforms like Washify and EverWash.
  • Vulnerability Discovery: Scans for exposed debug logs containing PII, directory listings in photo galleries, and vulnerable booking plugins.
  • Use Case: A security researcher can use this to quickly audit a list of local car wash websites to find exposed membership databases or insecure booking integrations.

Quick Start

Run the recon-carwashes skill against the target domain list provided in carwash-targets.txt to identify potential membership portal and plugin vulnerabilities.

Frequently Asked Questions about recon-carwashes

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I scan car wash websites for exposed PII and WordPress vulnerabilities?

Car wash website reconnaissance automates the detection of exposed PII in debug logs, directory listings in photo galleries, and vulnerable booking plugins using shell-based enumeration to identify common CMS vulnerabilities.

What security issues affect car wash membership portals and scheduling tools?

Car wash membership portals and scheduling tools often suffer from exposed debug logs containing PII, misconfigured shared hosting environments, and vulnerable WordPress booking plugin integrations that automated reconnaissance can detect.

Can I use automated reconnaissance to audit WordPress booking plugins for small businesses?

Automated reconnaissance can audit small-to-medium business infrastructure by targeting WordPress booking plugins and third-party integration weaknesses specific to platforms like Washify and EverWash.

How do I find misconfigured WordPress debug logs in auto detailing websites?

Finding misconfigured WordPress debug logs in auto detailing websites requires shell-based enumeration to scan for exposed logs containing PII and directory listings in public photo galleries.

What is the best way to enumerate subdomains for car wash management platforms?

Enumerating subdomains for car wash management platforms involves sector-specific reconnaissance to identify portals associated with common platforms like Washify and EverWash and detect third-party integration weaknesses.

Does this car wash vulnerability scanner work with a custom target domain list?

The car wash vulnerability scanner processes target domains from a provided text file list to identify potential membership portal and plugin vulnerabilities across multiple car wash websites.