recon-plumbing

Automate reconnaissance of WordPress plumbing sites for PII exposure and misconfigurations.

3|1|Updated Jul 2, 2026
One-click install
npx skills add https://github.com/EntroVyx/hermes-agent-offsec --skill recon-plumbing-entrovyx
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: recon-plumbing
Source: https://github.com/EntroVyx/hermes-agent-offsec/tree/main/skills/offsec/redteam/recon-plumbing
Command: npx skills add https://github.com/EntroVyx/hermes-agent-offsec --skill recon-plumbing-entrovyx

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill addresses the inefficiency of manual reconnaissance on small-to-medium business websites by automating the discovery of sensitive data, misconfigurations, and PII exposure specific to the plumbing and emergency service sector.

Core Features & Use Cases

  • Sector-Specific Discovery: Identifies WordPress-based plumbing sites and probes for common vulnerabilities like debug log exposure, directory listing, and insecure contact forms.
  • PII & Financial Recon: Scans for exposed customer data in logs, insecure payment endpoints, and unauthenticated drain camera inspection media.
  • Use Case: Quickly audit a list of plumbing company domains to identify exposed emergency service request logs or publicly accessible sewer inspection videos that could lead to data breaches.

Quick Start

Execute the recon-plumbing skill against the target domain list provided in the plumbing-targets.txt file to initiate the automated discovery process.

Frequently Asked Questions about recon-plumbing

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I find exposed PII and debug logs on WordPress plumbing websites?

To find exposed PII on WordPress plumbing sites, you can automate sector-specific reconnaissance to scan for debug log exposure, insecure contact form uploads, and unauthenticated media directories containing sensitive customer data.

Can I scan for unauthenticated media directories on small business service sites?

Yes, you can scan unauthenticated media directories on small business service sites by targeting WordPress-based infrastructure to identify publicly accessible drain camera inspection videos and unprotected business logic endpoints.

How do I automate endpoint enumeration and CORS analysis for emergency service domains?

Automate endpoint enumeration and CORS analysis for emergency service domains by leveraging shell-based network utilities to perform domain discovery and identify security misconfigurations across the target list.

What is the best way to audit a list of plumbing company domains for data exposure?

The best way to audit plumbing company domains for data exposure is executing automated reconnaissance against a provided target list to identify insecure payment endpoints, exposed service request logs, and directory listing vulnerabilities.

Do I need a specific target list file to start reconnaissance on plumbing websites?

Yes, you need a target domain list like a plumbing-targets.txt file to initiate the automated discovery process and systematically probe WordPress infrastructure for security misconfigurations and PII exposure.