What problem does it solve?
Generic reconnaissance tools miss sector-specific vulnerabilities in gym and fitness center websites, which commonly use specialized booking platforms and member portals with unique security gaps that are frequently exploited in real-world engagements.
Core Features & Use Cases
- Sector Platform Fingerprinting: Identifies common gym SaaS platforms (Mindbody, Mariana Tek, ClubReady) and underlying content management systems (WordPress, custom PHP, Wix, Squarespace).
- Booking & API Recon: Discovers exposed class schedule, booking, and member APIs that often leak personally identifiable information or allow insecure direct object reference (IDOR) attacks.
- Payment & Portal Testing: Checks for misconfigured payment integrations and unauthenticated access to member portals and profile endpoints.
- Use Case: For example, during a pentest of a boutique fitness studio, this skill can locate hardcoded Mindbody API keys in JavaScript bundles or unauthenticated endpoints that expose member check-in history and personal details.
Quick Start
Use the recon-gyms skill to perform full sector-specific reconnaissance on the target gym website and identify all exploitable booking, portal, and payment vulnerabilities.