What problem does it solve?
This Skill reduces the time and uncertainty involved in authorized external web reconnaissance by systematically finding exposed endpoints, security weaknesses, infrastructure clues, and documentation leaks.
Core Features & Use Cases
- Web and API Enumeration: Discover Swagger, OpenAPI, GraphQL, JavaScript, source map, and legacy endpoints across alive web applications.
- Security Posture Analysis: Assess HTTP security headers, email authentication controls, vendor fingerprints, subdomain takeover indicators, and exposed cloud storage.
- Evidence-Backed Triage: Classify observations by severity, preserve evidence references, score endpoint interest, and hand off qualified leads to related security workflows.
- Use Case: During an authorized bug-bounty engagement, use this Skill to identify an unauthenticated API specification, exposed internal hostnames, weak DMARC policy, and a potentially claimable subdomain without performing exploitation.
Quick Start
Use the web-surface skill to enumerate and prioritize exposed API, endpoint, email-security, vendor, cloud-storage, and documentation findings for an authorized target.