recon-osint

Aggregate public data from search engines, DNS, and repositories for passive reconnaissance.

Updated Jul 30, 2026
One-click install
npx skills add https://github.com/salmanabdurrahman/pi-pentest-agent --skill recon-osint-salmanabdurrahman
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: recon-osint
Source: https://github.com/salmanabdurrahman/pi-pentest-agent/tree/main/skills/recon-osint
Command: npx skills add https://github.com/salmanabdurrahman/pi-pentest-agent --skill recon-osint-salmanabdurrahman

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill solves the challenge of gathering comprehensive intelligence on a target's digital footprint without triggering security alerts or violating privacy, by centralizing passive reconnaissance workflows.

Core Features & Use Cases

  • Passive Intelligence Gathering: Aggregates data from search engines, DNS records, code repositories, and public breach databases without direct target contact.
  • Surface Mapping: Identifies subdomains, exposed configuration files, and infrastructure history to build a complete picture of the target's attack surface.
  • Use Case: Use this skill during the initial phase of an authorized pentest to discover leaked API keys in public GitHub repositories or identify misconfigured cloud storage buckets before moving to active probing.

Quick Start

Use the recon-osint skill to perform a passive reconnaissance scan on the target domain example.com while adhering to the defined scope file.

Frequently Asked Questions about recon-osint

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is passive reconnaissance and how does it gather OSINT data?

Passive reconnaissance collects OSINT data from public third-party sources like search engines, DNS records, and code repositories without directly contacting the target, avoiding security alerts while mapping the digital footprint.

How do I perform passive OSINT collection on a target domain?

You perform passive OSINT collection by aggregating public data from search engines, DNS records, and breach databases to identify subdomains, exposed configurations, and infrastructure history while adhering to strict scope boundaries.

Can I use passive reconnaissance to find leaked API keys in GitHub repositories?

Yes, passive reconnaissance can discover leaked API keys in public code repositories and identify misconfigured cloud storage buckets by aggregating publicly available data without triggering direct target interaction.

Does passive OSINT collection require manual verification of findings?

Yes, passive OSINT collection requires manual verification of findings to ensure compliance with safety policies and strict scope boundaries defined during authorized security assessment workflows.

What is the best way to map a target's attack surface without active probing?

The best way to map an attack surface without active probing is passive surface mapping, which identifies exposed configuration files, subdomains, and infrastructure history through centralized public data aggregation.

When should I not use passive reconnaissance for security assessments?

You should not use passive reconnaissance when real-time target interaction is required or when public data aggregation fails to meet the strict scope boundaries and compliance requirements of your security assessment.