recon-security

Coordinate and execute authorized external penetration tests from reconnaissance to reporting using free, open-source tools and structured evidence management.

76|11|Updated May 18, 2026
One-click install
npx skills add https://github.com/superagent-ai/skills --skill recon-security
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: recon-security
Source: https://github.com/superagent-ai/skills/tree/main/skills/recon-security
Command: npx skills add https://github.com/superagent-ai/skills --skill recon-security

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This skill provides a model-guided framework to run authorized external penetration tests from recon to reporting, helping teams map attack surfaces without relying on paid APIs.

Core Features & Use Cases

  • End-to-end engagement lifecycle guidance: recon, normalization, active discovery, web/app checks, validation, and reporting.
  • Guardrails and scoping: enforce RoE, risk controls, and evidence management; safe for teams with limited tooling.
  • Open-source tooling emphasis: leverages free/open-source scanners and local workflows for reproducible results.

Quick Start

Define scope and RoE, then begin passive reconnaissance with open-source tools to seed targets and evidence structure.

Frequently Asked Questions about recon-security

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I run an authorized external penetration test using open-source tools?

To run an authorized external penetration test, define your scope and Rules of Engagement, then execute passive reconnaissance with open-source scanners to seed targets and structure evidence for reproducible results.

What is evidence management in a pentesting workflow?

Evidence management in a pentesting workflow is the structured collection and normalization of reconnaissance data across web and infrastructure targets to ensure safe, reproducible engagements.

Can I map attack surfaces without relying on paid APIs?

You can map attack surfaces without paid APIs by leveraging free, open-source scanners within a model-guided framework to coordinate active discovery and web application checks.

What are the guardrails for executing safe external penetration tests?

Guardrails for safe external penetration tests involve enforcing Rules of Engagement, applying risk controls, and maintaining structured evidence management to protect teams with limited tooling.

Does model-guided reconnaissance work for both web and infrastructure targets?

Model-guided reconnaissance works for both web and infrastructure targets by coordinating end-to-end active discovery, validation, and reporting workflows across the engagement lifecycle.