recon-hvac

Performs targeted reconnaissance of HVAC company websites for sector-specific vulnerabilities.

1.1k|191|Updated Jun 24, 2026
One-click install
npx skills add https://github.com/uphiago/recon-skills --skill recon-hvac
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: recon-hvac
Source: https://github.com/uphiago/recon-skills/tree/main/redteam/recon-hvac
Command: npx skills add https://github.com/uphiago/recon-skills --skill recon-hvac

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

HVAC company websites are frequently built by local agencies using cookie-cutter WordPress configurations, have urgent emergency booking features with lax security validation, and store sensitive customer PII in maintenance plan portals and form uploads, making them high-value targets that require tailored recon techniques to identify common, sector-specific vulnerabilities that generic recon workflows miss.

Core Features & Use Cases

  • Sector-specific domain discovery: Targets HVAC company naming conventions and SEO-driven domain patterns to find all associated assets.
  • Feature-focused vulnerability checks: Specialized scans for common HVAC site features like emergency booking forms, maintenance plan portals, and smart thermostat integrations that often expose unauthenticated data or API keys.
  • Pre-built WordPress and plugin checks: Tests for WordPress configurations, debug logs, and plugins commonly used across HVAC sites built by local agencies, with real-world examples of observed vulnerabilities in the sector. Use case: A pentester targeting an HVAC company can use this skill to quickly identify exposed debug logs with customer PII, directory listings with service invoices, or unauthenticated access to maintenance plan customer data, rather than running generic web recon that misses these sector-specific weaknesses.

Quick Start

Use the recon-hvac skill to perform a full sector-specific recon of the target HVAC company domain, including domain discovery, WordPress configuration checks, and feature-specific vulnerability scanning for common HVAC site assets.

Frequently Asked Questions about recon-hvac

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I find vulnerabilities in HVAC company websites during a pentest?

To find HVAC website vulnerabilities, perform targeted reconnaissance for sector-specific weaknesses like exposed WordPress debug logs, unauthenticated maintenance plan portals, and emergency booking form validation flaws. This tailored approach identifies exposed customer PII that generic web enumeration tools often miss.

Why does generic web recon miss exposures on WordPress sites built by local agencies?

Generic web recon misses exposures on agency-built WordPress sites because it lacks checks for cookie-cutter plugin configurations and sector-specific features. Tailored scanning is required to detect common HVAC assets, such as smart thermostat integrations and exposed service invoice directory listings.

What is the best way to scan HVAC maintenance plan portals for unauthenticated data access?

The best way to scan HVAC maintenance plan portals for unauthenticated data access is using feature-focused vulnerability checks designed for sector assets. This specialized testing identifies exposed customer PII and API keys in maintenance portals that generic scanning workflows overlook.

Can I use sector-specific recon for red team engagements targeting smart thermostat integrations?

You can use sector-specific recon for red team engagements targeting smart thermostat integrations by applying specialized scans for HVAC features. This process identifies exposed API keys and unauthenticated data endpoints within smart thermostat configurations commonly found on HVAC service provider websites.

How do I run a full security assessment of an HVAC service provider's domain?

To run a full security assessment of an HVAC domain, execute targeted reconnaissance covering domain discovery, WordPress configuration checks, and vulnerability scanning for features like emergency booking forms. This uncovers exposed sensitive customer data across all associated web assets.

What limitations exist when testing emergency booking forms on HVAC service websites?

Testing emergency booking forms on HVAC websites is limited by the need for tailored recon workflows that account for agency-built configuration patterns. Generic vulnerability scanning may produce false negatives if it does not account for the unique technical stack and lax security validation of urgent booking features.