Recon

Automate security reconnaissance of domains, IPs, and netblocks.

1|Updated Jan 24, 2026
One-click install
npx skills add https://github.com/verrio1/vaughn-pai --skill recon-verrio1
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: Recon
Source: https://github.com/verrio1/vaughn-pai/tree/main/skills/Recon
Command: npx skills add https://github.com/verrio1/vaughn-pai --skill recon-verrio1

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

The Recon skill provides a structured approach to gather public-domain intelligence and map an organization's network perimeter, enabling faster threat assessments and targeted testing.

Core Features & Use Cases

  • Passive and OSINT-driven reconnaissance for domains, IPs, netblocks, and ASN mapping.
  • OSINT integration to surface subdomains, hosting providers, and attribution for risk assessment.
  • Supported workflows for both passive reconnaissance and authorized active testing with clear output and audit trails.

Quick Start

To begin, request: "Recon domain example.com" to generate a domain infrastructure map, then review the scratch/work reports.

Frequently Asked Questions about Recon

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I map an organization's attack surface using OSINT?

Attack surface mapping using OSINT automates the discovery of public-facing domains, subdomains, IPs, and netblocks to reveal infrastructure vulnerabilities. It surfaces hosting providers and attribution data for faster threat assessments.

What is passive reconnaissance for network infrastructure?

Passive reconnaissance gathers public-domain intelligence without directly interacting with the target's network. It maps ASN data, netblocks, and subdomains to support audits and threat assessment while maintaining stealth.

How do I enumerate subdomains and netblocks for a specific domain?

Enumerate subdomains and netblocks by requesting reconnaissance on a target domain. The process produces structured outputs detailing the infrastructure map, which integrates with reporting and logging systems for pentest engagements.

Can I perform active probing for authorized security testing?

Yes, authorized active probing is supported alongside passive gathering for infrastructure mapping. It produces clear audit trails and structured outputs to ensure compliance during targeted pentest engagements.

Does this reconnaissance approach integrate with existing reporting workflows?

Yes, the reconnaissance outputs are structured to integrate directly with reporting, logging, and workflow systems. This supports audits and pentest engagements by providing actionable infrastructure maps and threat assessment data.