recon-roofing

Enumerate roofing company domains, WordPress assets, and insurance claim endpoints.

1.1k|191|Updated Jun 24, 2026
One-click install
npx skills add https://github.com/uphiago/recon-skills --skill recon-roofing
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: recon-roofing
Source: https://github.com/uphiago/recon-skills/tree/main/redteam/recon-roofing
Command: npx skills add https://github.com/uphiago/recon-skills --skill recon-roofing

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Roofing company websites represent a high-value, often under-secured target class with unique attack surfaces including lead capture forms storing customer PII, insurance claim processing pages, and prevalent WordPress misconfigurations from SEO agency-built sites that generic reconnaissance tools fail to address.

Core Features & Use Cases

  • Sector-specific domain discovery: Enumerates roofing company domains using common naming conventions (city+roofing, storm restoration) and crt.sh certificate transparency logs.
  • WordPress and form asset scanning: Detects exposed contact form exports, debug logs with sensitive customer data, and common WordPress vulnerabilities (CORS misconfigurations, enabled XMLRPC) standard on SEO-built roofing sites.
  • Insurance claim surface mapping: Locates insurance claim assistance pages, document upload endpoints, and other high-value targets unique to the roofing sector. Use case: A penetration tester scoping a roofing company engagement can use this skill to quickly identify exposed lead CSV files with customer PII and unsecured insurance document upload forms without manual sifting through generic recon results.

Quick Start

Use the recon-roofing skill to enumerate all subdomains, exposed WordPress assets, and insurance claim-related endpoints for the target roofing company domain example-roofing.com.

Frequently Asked Questions about recon-roofing

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I find exposed customer PII on roofing company websites during a pentest?

Roofing company websites often expose customer PII through unsecured lead capture form exports and debug logs. This reconnaissance identifies those sector-specific endpoints alongside WordPress misconfigurations to accelerate vulnerability discovery during penetration tests.

What is the best way to enumerate WordPress misconfigurations on roofing sector domains?

The best way to enumerate WordPress misconfigurations on roofing domains is to target prevalent SEO agency-built site flaws like CORS misconfigurations and enabled XMLRPC. This approach maps insurance claim surfaces while detecting exposed form data.

Does generic reconnaissance find insurance claim processing endpoints on roof repair sites?

Generic reconnaissance tools frequently miss insurance claim processing endpoints on roof repair sites. Sector-specific enumeration is needed to locate document upload forms and claim assistance pages that represent high-value attack surfaces.

Can I use certificate transparency logs to discover storm damage restoration company domains?

Yes, you can use crt.sh certificate transparency logs to discover storm damage restoration company domains. This method leverages common naming conventions like city plus roofing to enumerate target assets effectively.

What limitations exist when scanning for exposed lead CSV files on roofing websites?

Scanning for exposed lead CSV files on roofing websites is limited to identifying known sector-specific endpoints and WordPress form assets. It relies on prevalent SEO-built site misconfigurations and cannot predict custom unknown vulnerabilities.