recon-moving-companies

Automate security reconnaissance of moving company websites for PII leaks and configuration vulnerabilities.

3|1|Updated Jul 2, 2026
One-click install
npx skills add https://github.com/EntroVyx/hermes-agent-offsec --skill recon-moving-companies-entrovyx
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: recon-moving-companies
Source: https://github.com/EntroVyx/hermes-agent-offsec/tree/main/skills/offsec/redteam/recon-moving-companies
Command: npx skills add https://github.com/EntroVyx/hermes-agent-offsec --skill recon-moving-companies-entrovyx

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill automates the discovery of security vulnerabilities in moving and relocation company websites, which often suffer from exposed customer PII and weak configuration due to the use of shared hosting and insecure WordPress plugins.

Core Features & Use Cases

  • PII Exposure Detection: Identifies exposed debug logs and directory listings that leak customer names, addresses, and inventory lists.
  • Platform-Specific Recon: Scans for common moving industry platforms like MovePoint and OTRS, as well as vulnerable WordPress configurations.
  • Use Case: Use this skill to audit a regional moving company's web presence to identify if their quote request forms are leaking sensitive customer data via insecure file uploads or debug logs.

Quick Start

Use the recon-moving-companies skill to perform a full security audit on the target domain example-movers.com.

Frequently Asked Questions about recon-moving-companies

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I scan a moving company website for exposed PII and configuration vulnerabilities?

To check WordPress quote forms for PII leaks, scan for insecure file uploads, exposed debug logs, and directory listings that reveal customer names, addresses, and inventory lists. This identifies vulnerabilities caused by weak configurations and insecure plugins.

What types of security vulnerabilities are common in moving and logistics websites?

Common security vulnerabilities in moving and logistics websites include exposed customer PII, directory listings, debug log exposure, and insecure API endpoints. These issues frequently result from shared hosting and weak WordPress plugin configurations.

Can I use automated reconnaissance to detect insecure API endpoints in relocation platforms?

Yes, automated reconnaissance detects insecure API endpoints in relocation platforms by executing systematic checks on customer portals and CRM integrations. This targets WordPress-based forms to map the attack surface and identify configuration vulnerabilities.

Does this reconnaissance approach work with MovePoint and OTRS platforms?

Yes, this reconnaissance approach works with MovePoint and OTRS platforms. It performs platform-specific recon to scan for common moving industry platforms alongside vulnerable WordPress configurations to identify exposed customer data.

Why do moving company websites suffer from exposed customer data?

Moving company websites suffer from exposed customer data due to shared hosting and insecure WordPress plugins. This leads to exposed debug logs and directory listings that leak sensitive customer names, addresses, and inventory lists.