recon-for-sec

Map target scope and identify assets for security reconnaissance.

1.6k|204|Updated Apr 7, 2026
One-click install
npx skills add https://github.com/yaklang/hack-skills --skill recon-for-sec
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: recon-for-sec
Source: https://github.com/yaklang/hack-skills/tree/main/skills/recon-for-sec
Command: npx skills add https://github.com/yaklang/hack-skills --skill recon-for-sec

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve? Provides a structured starting point for security engagements by mapping target scope, identifying assets, fingerprinting technology, building an endpoint inventory, and selecting the initial high-value testing path.

Core Features & Use Cases - Structured routing: guides testers from discovery to the most valuable next steps. - Asset-centric planning: prioritizes assets and technologies likely to yield leverage early. - Scalable scope mapping: supports onboarding of new targets and evolving engagements. - Use Case: Begin a new engagement by mapping scope, inventorying endpoints, and routing to subsequent skills such as api-sec, auth-sec, or injection-checking.

Quick Start Describe the target environment, map scope, and route to the next relevant skills.

Frequently Asked Questions about recon-for-sec

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I plan reconnaissance for a new security engagement?

Plan reconnaissance by mapping the target scope, identifying assets, fingerprinting technology, and building an endpoint inventory to select the initial high-value testing path. This structured approach ensures comprehensive asset discovery before deeper testing begins.

What is the best way to map scope and inventory endpoints for security testing?

Mapping scope and inventorying endpoints involves structured input, routing decisions, and stepwise asset discovery guidance. This methodology prioritizes assets and technologies likely to yield leverage early in the engagement.

Can I route reconnaissance findings to specific security testing skills?

Yes, reconnaissance findings route directly into subsequent skills like api-sec, auth-sec, or injection-checking. Structured routing guides testers from initial discovery to the most valuable next steps for specialized vulnerability analysis.

When do I need structured routing in security reconnaissance?

Structured routing is needed at project kickoff to enforce structured input and stepwise asset discovery. It ensures testers follow a guided path from scope mapping to selecting the most valuable subsequent testing actions.

Does asset-centric planning support onboarding new targets during an engagement?

Asset-centric planning supports scalable scope mapping, allowing the onboarding of new targets and evolving engagements. It maintains structured reconnaissance even as the target environment expands.

What limitations exist when using this methodology for scope mapping?

This methodology focuses strictly on reconnaissance planning, scope mapping, and routing. It does not execute the vulnerability checks itself; findings must route to subsequent specialized skills for actual security testing.