recon-mattress-stores

Identify security vulnerabilities and data exposure in mattress e-commerce websites.

3|1|Updated Jul 2, 2026
One-click install
npx skills add https://github.com/EntroVyx/hermes-agent-offsec --skill recon-mattress-stores-entrovyx
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: recon-mattress-stores
Source: https://github.com/EntroVyx/hermes-agent-offsec/tree/main/skills/offsec/redteam/recon-mattress-stores
Command: npx skills add https://github.com/EntroVyx/hermes-agent-offsec --skill recon-mattress-stores-entrovyx

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill automates the discovery of security misconfigurations and data leakage points specific to mattress and bedding e-commerce platforms, which often rely on complex third-party financing and store locator integrations.

Core Features & Use Cases

  • Platform Fingerprinting: Automatically identifies Shopify, WooCommerce, and BigCommerce backends.
  • API & Financing Audit: Probes for exposed financing APIs (Affirm, Klarna, Bread) and unauthenticated REST API endpoints.
  • Use Case: Quickly identify if a mattress retailer's store locator API is leaking manager PII or if their WooCommerce instance has an exposed, unauthenticated coupon management endpoint.

Quick Start

Use the recon-mattress-stores skill to perform a full security audit on the target domain example-mattress-store.com.

Frequently Asked Questions about recon-mattress-stores

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I find exposed financing APIs in WooCommerce and Shopify mattress stores?

To find exposed financing APIs, probe endpoints for Affirm, Klarna, and Bread misconfigurations on mattress retail sites. This process targets unauthenticated REST API endpoints to identify vulnerabilities and sensitive data exposure in Shopify and WooCommerce bedding platforms.

What is store locator data leakage in e-commerce recon?

Store locator data leakage in e-commerce recon occurs when mattress retailer locator APIs expose manager PII. Probing these endpoints and analyzing frontend assets reveals unprotected sensitive information, highlighting a critical data exposure vulnerability.

Can I audit unauthenticated coupon management endpoints on BigCommerce?

Yes, you can audit unauthenticated coupon management endpoints on BigCommerce and WooCommerce. The recon process targets these misconfigurations to identify coupon code manipulation vulnerabilities and data exposure points within mattress and bedding e-commerce platforms.

Does e-commerce pentest recon work for niche retail like mattress stores?

E-commerce pentest recon works for mattress stores by targeting complex third-party financing and store locator integrations. It fingerprints Shopify and WooCommerce backends to discover security misconfigurations specific to the bedding industry.

Do I need standard web reconnaissance tools to probe mattress store APIs?

Yes, you need standard web reconnaissance tools to probe mattress store APIs and analyze frontend assets. These tools are required to discover security vulnerabilities, data exposure, and financing integration misconfigurations on Shopify and WooCommerce platforms.