recon-fire-restoration

Automate security reconnaissance of WordPress restoration sites to detect PII leaks and misconfigurations.

3|1|Updated Jul 2, 2026
One-click install
npx skills add https://github.com/EntroVyx/hermes-agent-offsec --skill recon-fire-restoration-entrovyx
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: recon-fire-restoration
Source: https://github.com/EntroVyx/hermes-agent-offsec/tree/main/skills/offsec/redteam/recon-fire-restoration
Command: npx skills add https://github.com/EntroVyx/hermes-agent-offsec --skill recon-fire-restoration-entrovyx

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill automates the identification of security vulnerabilities in fire and water damage restoration company websites, which often handle sensitive customer PII and insurance data.

Core Features & Use Cases

  • Sector-Specific Recon: Identifies common CMS platforms like WordPress and CRM tools like ServiceTitan used in the restoration industry.
  • Vulnerability Discovery: Detects exposed debug logs, CORS misconfigurations, and sensitive directory listings that could leak property addresses or insurance claims.
  • Use Case: Use this skill to audit a restoration company's web presence to identify if their emergency intake forms or photo galleries are inadvertently exposing customer PII or internal franchise data.

Quick Start

Use the recon-fire-restoration skill to perform a full security audit on the target domain example-restoration.com.

Frequently Asked Questions about recon-fire-restoration

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I find CORS misconfigurations and exposed debug logs on WordPress restoration sites?

To find CORS misconfigurations and exposed debug logs on WordPress restoration sites, perform targeted security reconnaissance using standard HTTP request tools to map the attack surface and validate configuration vulnerabilities. This identifies sensitive directory listings that could leak property addresses or insurance claims.

What security vulnerabilities are common in fire and water damage restoration company websites?

Common security vulnerabilities in fire and water damage restoration company websites include exposed debug logs, CORS misconfigurations, and sensitive directory listings. These platforms handle sensitive customer PII and insurance data, making franchise-specific CRM integrations prime targets for configuration vulnerabilities.

Do I need specialized network utilities to audit emergency intake forms for PII leaks?

You do not need specialized network utilities to audit emergency intake forms for PII leaks. This reconnaissance requires only standard network utilities and HTTP request tools to map attack surfaces, validate exploit chains, and detect if forms inadvertently expose customer PII.

Can I use standard HTTP request tools to map the attack surface of ServiceTitan CRM integrations?

You can use standard HTTP request tools to map the attack surface of ServiceTitan CRM integrations. This reconnaissance targets franchise-specific CRM integrations on WordPress platforms to uncover exposed directories and validate potential exploit chains that leak internal franchise data.

What is the best way to automate vulnerability discovery for WordPress platforms in the restoration industry?

The best way to automate vulnerability discovery for WordPress platforms in the restoration industry is to run sector-specific security reconnaissance that identifies common CMS platforms and CRM tools. This detects exposed sensitive directory listings and PII leaks from photo galleries or emergency intake forms.