recon-dentists

Identify PHI exposure risks and vulnerabilities in dental practice websites.

1.1k|191|Updated Jun 24, 2026
One-click install
npx skills add https://github.com/uphiago/recon-skills --skill recon-dentists
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: recon-dentists
Source: https://github.com/uphiago/recon-skills/tree/main/redteam/recon-dentists
Command: npx skills add https://github.com/uphiago/recon-skills --skill recon-dentists

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Dental practice websites frequently handle sensitive protected health information (PHI) with minimal security investment, making them high-value targets for data breaches. This Skill solves the problem of identifying overlooked security gaps and sensitive data exposure risks in these sector-specific web assets.

Core Features & Use Cases

  • Sector-specific domain discovery: Locate dental practice, orthodontic, and oral surgery websites using targeted dorks and certificate transparency searches.
  • Common tech stack recon: Enumerate WordPress installations, booking systems (Dentrix Ascend, Eaglesoft), and patient portals (PatientConnect) for known vulnerabilities.
  • High-value finding detection: Identify exposed debug logs with patient PII, CORS credential reflection flaws, and IDOR vulnerabilities in appointment booking APIs.
  • Use Case: For an authorized penetration test of a dental clinic network, use this Skill to quickly map their web presence, find exposed patient data, and prioritize attack chains specific to their common technology stack.

Quick Start

Use the recon-dentists skill to perform a full sector-specific reconnaissance of a target dental practice website to identify PHI exposure risks and common attack surfaces.

Frequently Asked Questions about recon-dentists

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I scan dental practice websites for PHI exposure risks?

Scanning dental practice websites for PHI exposure risks involves identifying exposed debug logs with patient PII, CORS credential reflection flaws, and IDOR vulnerabilities in appointment booking APIs during authorized penetration tests.

What security vulnerabilities affect dental clinic WordPress sites and patient portals?

Security vulnerabilities affecting dental clinic WordPress sites and patient portals include CMS enumeration flaws, sensitive path detection issues, and exposed patient data resulting from minimal security investment in PHI handling.

How do I enumerate dental practice tech stacks like Dentrix Ascend and Eaglesoft during a pentest?

Enumerating dental practice tech stacks like Dentrix Ascend and Eaglesoft during a pentest requires applying targeted domain discovery and CMS enumeration to map booking systems and patient portals for known vulnerabilities.

Does recon-dentists work for orthodontic and oral surgery centers using PatientConnect?

Yes, reconnaissance techniques work for orthodontic and oral surgery centers using PatientConnect by satisfying sector-specific requirements for domain discovery, CMS enumeration, sensitive path detection, and attack chain identification.

What is the best way to find exposed patient data in dental clinic web assets?

Finding exposed patient data in dental clinic web assets is best achieved using targeted dorks and certificate transparency searches to locate high-value findings like exposed debug logs containing patient PII.

When should I use specialized dental recon instead of general vulnerability scanning?

Specialized dental recon should be used instead of general vulnerability scanning when targeting dental clinics, orthodontic practices, and oral surgery centers to identify attack chains specific to their common technology stack.