sn1per

Automate penetration-testing reconnaissance with over 20 security tools.

15|1|Updated Feb 12, 2026
One-click install
npx skills add https://github.com/AeonDave/malskill --skill sn1per
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: sn1per
Source: https://github.com/AeonDave/malskill/tree/main/offensive-tools/recon/sn1per
Command: npx skills add https://github.com/AeonDave/malskill --skill sn1per

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill automates comprehensive target reconnaissance for penetration testing, consolidating over 20 different tools into a single, efficient scan.

Core Features & Use Cases

  • Comprehensive Scanning: Combines port scanning, subdomain discovery, vulnerability detection, and more.
  • Automated Framework: Orchestrates tools like nmap, nikto, metasploit, and amass.
  • Use Case: When tasked with a full assessment of a target domain, use this Skill to automatically discover open ports, identify running services, find subdomains, and detect potential vulnerabilities.

Quick Start

Run a full recon scan on target.com.

Frequently Asked Questions about sn1per

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate reconnaissance for penetration testing across a target domain?

Automated reconnaissance for penetration testing is streamlined by orchestrating over 20 security tools into a single scan. This framework executes network discovery, port scanning, subdomain enumeration, and vulnerability detection automatically.

What is included in an automated full target recon scan?

A full target recon scan combines port scanning, subdomain discovery, web crawling, and vulnerability detection. By orchestrating tools like nmap, nikto, metasploit, and amass, it provides comprehensive target assessment in one operation.

Do I need Kali Linux to run automated vulnerability scanning and subdomain enumeration?

Automated vulnerability scanning and subdomain enumeration require Bash and Linux, with Kali recommended. You must also have the Sn1per framework installed from its official GitHub repository to execute the orchestrated security scans.

What's the best way to detect open ports and identify running services during network discovery?

The best way to detect open ports and identify running services is using an automated framework that orchestrates tools like nmap and amass. This approach consolidates network discovery and service identification into a single efficient scan.

Can I use this automated framework to find subdomains and detect potential vulnerabilities simultaneously?

Yes, you can find subdomains and detect potential vulnerabilities simultaneously. The framework automates comprehensive target reconnaissance by combining subdomain enumeration, web crawling, and vulnerability detection within a single scan execution.