techstack-identification

Identify a company's technology stack from public OSINT signals.

Updated Apr 23, 2026
One-click install
npx skills add https://github.com/YukiIto1999/ctf-sleuth --skill techstack-identification
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: techstack-identification
Source: https://github.com/YukiIto1999/ctf-sleuth/tree/main/.claude/skills/techstack-identification
Command: npx skills add https://github.com/YukiIto1999/ctf-sleuth --skill techstack-identification

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

OSINT-based technology stack identification. Discovers company tech stacks using passive reconnaissance across 17 intelligence domains. Given a company name (and optional domain hint), infers frontend, backend, infrastructure, and security technologies using publicly available signals.

Core Features & Use Cases

  • Passive OSINT reconnaissance to identify a target's technology stack. No credentials, no active scanning — only publicly available signals.
  • Phases run sequentially: asset discovery, data collection, tech inference, correlation, and report generation.
  • Use Case: Competitive analysis or vendor due diligence by mapping frontend/backend infrastructure and security technologies from public signals.

Quick Start

Analyze a company name and optional domain hint to generate a technology stack profile from public signals.

Frequently Asked Questions about techstack-identification

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I identify a company's technology stack using OSINT?

Identify a company's technology stack by running passive OSINT reconnaissance across 17 intelligence domains. The pipeline discovers assets, collects public signals, infers frontend and backend technologies, and generates a structured profile without active scanning or credentials.

Can I map a target's infrastructure and security technologies from public signals only?

Yes, you can map infrastructure and security technologies using only public signals. The analysis infers these technologies through passive data collection and correlation, assigning confidence scores without requiring credentials or active network scanning.

What's the best way to perform passive recon for vendor due diligence?

The best way to perform passive recon for vendor due diligence is to input a company name and optional domain hint. The sequential pipeline handles asset discovery, data collection, and tech inference to deliver a comprehensive stack report.

Do I need credentials or active scanning to fingerprint a company's tech stack?

No, you do not need credentials or active scanning to fingerprint a tech stack. The Skill strictly uses passive OSINT signals and publicly available sources to infer frontend, backend, and security technologies.

How does fingerprinting work across the 17 intelligence domains?

Fingerprinting across 17 intelligence domains works by correlating publicly available signals to infer specific technologies. The pipeline collects data across these domains, correlates the signals, and generates confidence scores for each identified technology.

What limitations exist when inferring a tech stack from publicly available signals?

A limitation of inferring a tech stack from public signals is reliance on passive data, meaning internal or proprietary technologies may remain hidden. Confidence scores help indicate the reliability of each inference made from the available data.