recon-workbench

Execute authorized interrogation workflows for macOS apps, web apps, and repositories.

8|4|Updated Jan 15, 2026
One-click install
npx skills add https://github.com/jscraik/Agent-Skills --skill recon-workbench
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: recon-workbench
Source: https://github.com/jscraik/Agent-Skills/tree/main/utilities/recon-workbench
Command: npx skills add https://github.com/jscraik/Agent-Skills --skill recon-workbench

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve?

This Skill provides a structured, evidence-first approach to interrogating digital targets, ensuring all findings are backed by verifiable artifacts and adhering to strict authorization and safety protocols.

Core Features & Use Cases

  • Authorized Interrogation: Executes workflows only after explicit authorization is confirmed.
  • Evidence-Based Findings: All conclusions are tied to specific artifact paths, preventing speculation.
  • Target Versatility: Supports macOS apps, iOS simulators, web applications, and open-source repositories.
  • Use Case: Securely investigate a web application for potential vulnerabilities by running a series of probes, capturing network traffic and execution traces, and generating a report detailing any identified risks with direct links to the supporting evidence.

Quick Start

Run an authorized baseline interrogation on the specified macOS application.

Frequently Asked Questions about recon-workbench

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform authorized security analysis on a macOS application?

Authorized security analysis on a macOS application requires providing specific target identifiers, probe sets, and authorization artifacts to initiate an interrogation run. The workflow executes evidence-backed probes and generates deterministic artifacts for validation.

What is evidence-based reconnaissance for web applications?

Evidence-based reconnaissance for web applications is an interrogation workflow that captures network traffic and execution traces to identify risks. All conclusions are tied to specific artifact paths, preventing speculation and ensuring verifiable findings.

Can I use target analysis probes on open-source repositories?

Yes, target analysis probes support open-source repositories alongside macOS apps, iOS simulators, and web applications. The interrogation workflow requires explicit authorization and specific inputs to execute safely and generate deterministic validation artifacts.

Do I need authorization artifacts to start an interrogation workflow?

Yes, authorization artifacts are strictly required to start an interrogation workflow. The system enforces explicit authorization confirmation and safety constraints before executing any target analysis probes or generating evidence-backed findings.

How do I validate findings from a security analysis probe set?

You validate findings from a security analysis probe set by reviewing the deterministic artifact paths generated during the run. All identified risks are directly linked to supporting evidence, preventing speculative conclusions during target interrogation.

What's the best way to investigate web application vulnerabilities without speculation?

The best way to investigate web application vulnerabilities without speculation is using an evidence-first interrogation approach. This method captures network traffic and execution traces, generating a report that links identified risks directly to supporting artifact paths.