recon-plumbing

Identify exposed PII, payment endpoints, and misconfigurations on plumbing company websites.

1.1k|191|Updated Jun 24, 2026
One-click install
npx skills add https://github.com/uphiago/recon-skills --skill recon-plumbing
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: recon-plumbing
Source: https://github.com/uphiago/recon-skills/tree/main/redteam/recon-plumbing
Command: npx skills add https://github.com/uphiago/recon-skills --skill recon-plumbing

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill fills the gap in generic reconnaissance workflows for plumbing service company websites, which have unique sector-specific assets, emergency service data flows, and customer financing portals that standard recon tools fail to identify.

Core Features & Use Cases

  • Sector-Targeted Domain Discovery: Finds plumbing company subdomains using common naming patterns and certificate transparency logs.
  • Sensitive Data Detection: Locates exposed PII from emergency service logs, contact form submissions, and WordPress debug logs.
  • Attack Surface Mapping: Discovers financing/payment endpoints, publicly accessible drain inspection media, and CORS misconfigurations common to plumbing SMB sites.

Quick Start

Use the recon-plumbing skill to perform full sector-specific reconnaissance on a target plumbing company domain and identify exposed PII, payment endpoints, and inspection media.

Frequently Asked Questions about recon-plumbing

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I find exposed PII in WordPress debug logs on plumbing company websites?

To find exposed PII in WordPress debug logs on plumbing company websites, perform sector-specific reconnaissance targeting emergency service data flows and contact form submissions. This process identifies unique attack surfaces where standard recon tools fail to locate sensitive customer data.

What is the best way to map attack surfaces for SMB plumbing service providers?

Mapping attack surfaces for SMB plumbing service providers requires targeted reconnaissance of emergency booking systems and customer financing portals. This approach discovers sector-specific subdomains using certificate transparency logs and common naming patterns unique to plumbing companies.

How do I locate exposed payment application endpoints during a red team engagement?

Locating exposed payment application endpoints during a red team engagement involves mapping financing portals common to plumbing SMB sites. Automated discovery identifies vulnerable payment endpoints and CORS misconfigurations that generic reconnaissance workflows often miss.

Can I use automated discovery to find directory listings of drain inspection media?

Yes, automated discovery can find directory listings of drain inspection media on plumbing company websites. Sector-targeted reconnaissance maps publicly accessible inspection media assets, alongside debug logs containing PII, specifically tailored for authorized penetration testing.

Does standard reconnaissance work for identifying CORS misconfigurations on plumbing WordPress sites?

Standard reconnaissance does not work effectively for identifying CORS misconfigurations on plumbing WordPress sites due to unique sector-specific assets and emergency service data flows. Specialized recon is required to discover these misconfigurations alongside exposed financing endpoints.

When do I need sector-specific reconnaissance for penetration testing tasks?

You need sector-specific reconnaissance for penetration testing tasks when targeting plumbing service companies with WordPress sites, emergency booking systems, and customer financing portals. Generic tools fail to identify unique sector assets like exposed inspection media and emergency service logs.