techstack-security

Analyze HTTP headers, DNS records, and security endpoints to catalog third-party SaaS vendors.

3|1|Updated May 26, 2026
One-click install
npx skills add https://github.com/LeoWSY-hashblue/-communitytools-custom --skill techstack-security
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: techstack-security
Source: https://github.com/LeoWSY-hashblue/-communitytools-custom/tree/main/skills/techstack-identification/security
Command: npx skills add https://github.com/LeoWSY-hashblue/-communitytools-custom --skill techstack-security

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Detect and quantify a target's security posture and third-party SaaS exposure by aggregating signals from HTTP security headers, CSP and HSTS configurations, email authentication records, and well-known endpoints to produce a structured risk view.

Core Features & Use Cases

  • Security posture analysis: evaluate header coverage, CSP directives, HSTS, and email-auth strength.
  • Third-party SaaS discovery: identify and catalog external services (analytics, payments, identity, CRM) that expand the attack surface.
  • Use Case: assess a new web application's external risk surface before a security assessment or penetration test.

Quick Start

Scan a target domain to assess its security posture and third-party SaaS exposure using the skill.

Frequently Asked Questions about techstack-security

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I assess a target's security posture and third-party SaaS exposure?

Identify third-party SaaS exposure by aggregating signals from HTTP security headers, CSP directives, DNS TXT records, and well-known endpoints to catalog external services like analytics, payments, and identity providers into a structured risk view.

What does an HTTP security header and CSP analysis include for risk assessment?

Evaluating HTTP security header coverage, CSP directives, HSTS configurations, and email authentication strength quantifies a target's external risk surface before a penetration test or security assessment.

Can I map supply-chain risk by detecting external SaaS vendors on a web property?

Detecting external SaaS vendors like analytics, payments, identity, and CRM services maps supply-chain risk by cataloging these third-party dependencies that expand a web property's attack surface.

How do I use DNS TXT records and well-known endpoints for a pre-engagement security baseline?

Analyzing DNS TXT records and well-known endpoints establishes a pre-engagement security baseline by identifying email authentication configurations and external service exposures before a penetration test.

Does this security posture analysis require any dependencies or component installations?

No dependencies or component installations are required to scan a target domain and assess its security posture and third-party SaaS exposure.