recon-pools

Identify pool service website vulnerabilities via domain and WordPress enumeration.

1.1k|191|Updated Jun 24, 2026
One-click install
npx skills add https://github.com/uphiago/recon-skills --skill recon-pools
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: recon-pools
Source: https://github.com/uphiago/recon-skills/tree/main/redteam/recon-pools
Command: npx skills add https://github.com/uphiago/recon-skills --skill recon-pools

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill fills a gap in standard reconnaissance workflows by providing targeted guidance for identifying unique vulnerabilities and high-value assets specific to pool service, pool construction, hot tub, and spa company websites, which often have distinct security weaknesses like exposed photo galleries with EXIF geolocation data, unauthenticated service portals, and exposed debug logs with customer PII that generic recon tools miss.

Core Features & Use Cases

  • Sector-specific domain discovery: Uses crt.sh to find pool-related subdomains for a target scope.
  • WordPress and asset enumeration: Detects directory listings of pool build photo galleries, exposed debug logs, and CORS misconfigurations on WordPress installations common to these businesses.
  • Service portal and payment system detection: Identifies unauthenticated client portals, booking systems, and payment integrations for further testing.
  • Use Case: A penetration tester targeting a regional pool construction company can use this Skill to quickly locate exposed before/after project photos with homeowner addresses, unauthenticated client portals with full customer service histories, and debug logs containing payment details and equipment serial numbers.

Quick Start

Use the recon-pools skill to conduct complete sector-specific reconnaissance on a target pool service or pool construction company domain, including WordPress asset discovery, service portal detection, and sensitive data exposure checks.

Frequently Asked Questions about recon-pools

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I find exposed customer PII and debug logs on pool service company websites?

To find exposed customer PII on pool service company websites, you can use sector-specific reconnaissance to detect exposed debug logs and directory listings. This approach targets distinct weaknesses like unauthenticated client portals common to these businesses.

What security vulnerabilities are unique to pool construction and hot tub business websites?

Security vulnerabilities unique to pool construction and hot tub websites include exposed photo galleries with EXIF geolocation data, unauthenticated service portals, and debug logs containing payment details. These sites often feature distinct weaknesses missed by generic recon tools.

How do I enumerate WordPress assets and directory listings for a pool service target?

To enumerate WordPress assets for a pool service target, this reconnaissance workflow detects directory listings of build photo galleries, exposed debug logs, and CORS misconfigurations. It applies targeted asset discovery to WordPress installations common to these businesses.

Can I use this reconnaissance approach for small to medium-sized spa and pool service businesses?

Yes, you can use this reconnaissance approach for small to medium-sized spa and pool service businesses. It is specifically designed for penetration testing and red team engagements targeting the pool services sector, covering domain discovery and portal detection.

What is the best way to discover unauthenticated client portals on pool service sites?

The best way to discover unauthenticated client portals on pool service sites is through targeted service portal detection. This reconnaissance identifies booking systems, payment integrations, and client portals exposing customer service histories for further testing.

Why does standard reconnaissance miss vulnerabilities on pool service company websites?

Standard reconnaissance misses vulnerabilities on pool service company websites because it lacks targeted guidance for sector-specific weaknesses like EXIF geolocation data in photo galleries and unrestricted third-party API keys. This approach fills that gap with focused discovery.