recon-pools

Automate sector-specific reconnaissance for WordPress pool service websites to detect security misconfigurations.

3|1|Updated Jul 2, 2026
One-click install
npx skills add https://github.com/EntroVyx/hermes-agent-offsec --skill recon-pools-entrovyx
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: recon-pools
Source: https://github.com/EntroVyx/hermes-agent-offsec/tree/main/skills/offsec/redteam/recon-pools
Command: npx skills add https://github.com/EntroVyx/hermes-agent-offsec --skill recon-pools-entrovyx

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill automates the identification of security vulnerabilities specific to pool service and construction company websites, which often suffer from poor maintenance and exposed sensitive data.

Core Features & Use Cases

  • Sector-Specific Recon: Identifies common misconfigurations in WordPress-based pool service sites, such as exposed debug logs and directory listings.
  • Data Leak Detection: Scans for exposed EXIF geolocation data in project galleries and PII in debug logs.
  • Use Case: Quickly audit a list of pool service domains to find exposed client portals, payment system integrations, or sensitive project photos that reveal homeowner addresses.

Quick Start

Use the recon-pools skill to perform a full security audit on the target domain example-pool-service.com.

Frequently Asked Questions about recon-pools

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I scan pool service WordPress sites for exposed debug logs and directory listings?

To scan pool service WordPress sites for exposed debug logs and directory listings, this skill automates endpoint analysis to detect common security misconfigurations in poorly maintained infrastructure. It targets sector-specific vulnerabilities using standard curl and python3 environments to discover exposed sensitive data.

What reconnaissance techniques find PII and EXIF geolocation data leaks in service company websites?

Reconnaissance techniques for finding PII and EXIF geolocation data leaks involve scanning project galleries for embedded metadata and parsing exposed debug logs. This skill automates data leak detection to identify homeowner addresses and sensitive client information left exposed on pool service domains.

Do I need curl and python3 to perform automated security audits on pool service domains?

Yes, you need standard curl and python3 environments to perform automated security audits on pool service domains. These dependencies are required to execute domain discovery, endpoint analysis, and vulnerability detection scripts for identifying insecure client portals.

Can I detect insecure client portals and exposed payment integrations on construction company websites?

Yes, you can detect insecure client portals and exposed payment integrations on construction company websites by running targeted sector-specific reconnaissance. The skill audits target domains to find exposed sensitive data and misconfigurations in WordPress-based infrastructure.

What is the best way to automate vulnerability discovery for WordPress-based pool and spa service sites?

The best way to automate vulnerability discovery for WordPress-based pool and spa service sites is using a targeted reconnaissance skill that identifies sector-specific misconfigurations. It detects exposed debug logs, directory listings, and data leaks requiring standard curl and python3.