recon-solar-installers

Identify exposed API keys and security misconfigurations on solar installer websites.

3|1|Updated Jul 2, 2026
One-click install
npx skills add https://github.com/EntroVyx/hermes-agent-offsec --skill recon-solar-installers-entrovyx
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: recon-solar-installers
Source: https://github.com/EntroVyx/hermes-agent-offsec/tree/main/skills/offsec/recon-solar-installers
Command: npx skills add https://github.com/EntroVyx/hermes-agent-offsec --skill recon-solar-installers-entrovyx

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill automates the identification of high-value attack surfaces within solar energy company websites, which often contain sensitive financial data and insecure custom integrations.

Core Features & Use Cases

  • Sector-Specific Recon: Identifies subdomains and endpoints unique to solar installers, such as financing calculators and referral portals.
  • Vulnerability Discovery: Scans for exposed debug logs, API keys in client-side JavaScript, and IDOR-prone referral tracking.
  • Use Case: Use this skill to audit a solar company's web presence for exposed loan application forms or embedded energy monitoring API keys that could lead to unauthorized data access.

Quick Start

Run the recon-solar-installers skill against the target domain example-solar-company.com to identify exposed financing endpoints and potential API key leaks.

Frequently Asked Questions about recon-solar-installers

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I find exposed API keys in solar company websites?

To find exposed API keys in solar company websites, perform reconnaissance on client-side JavaScript and custom integrations like financing calculators. This skill automates identifying high-value targets and security misconfigurations within renewable energy platforms.

What is the best way to discover IDOR vulnerabilities in solar referral portals?

The best way to discover IDOR vulnerabilities in solar referral portals is to scan subdomains and endpoints unique to solar installers. This skill targets referral tracking systems to identify insecure custom integrations and potential unauthorized data access.

Can I audit solar financing calculators for security misconfigurations?

Yes, you can audit solar financing calculators for security misconfigurations by analyzing domain patterns and client-side JavaScript. This skill maps the attack surface of renewable energy platforms to locate exposed loan application forms.

Do I need specialized network utilities for solar infrastructure reconnaissance?

Solar infrastructure reconnaissance requires standard network utilities and common web reconnaissance tools rather than specialized software. This skill leverages existing tools to map the attack surface of renewable energy platforms and identify sensitive financial data.

Why do solar installation websites often contain insecure custom integrations?

Solar installation websites often contain insecure custom integrations because they handle sensitive financial data through loan applications and energy monitoring APIs. This skill identifies these high-value attack surfaces and exposed debug logs.

How do I map the attack surface of renewable energy platforms?

To map the attack surface of renewable energy platforms, analyze subdomains and endpoints unique to solar installers. This skill identifies exposed financing endpoints, referral portals, and embedded energy monitoring API keys.