web-surface

Enumerate authorized web surfaces and convert exposed endpoints into prioritized reconnaissance leads.

4|Updated Apr 29, 2026
One-click install
npx skills add https://github.com/Ap6pack/outrider-recon --skill web-surface
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: web-surface
Source: https://github.com/Ap6pack/outrider-recon/tree/main/skills/web-surface
Command: npx skills add https://github.com/Ap6pack/outrider-recon --skill web-surface

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill reduces the time and uncertainty involved in authorized external web reconnaissance by systematically finding exposed endpoints, security weaknesses, infrastructure clues, and documentation leaks.

Core Features & Use Cases

  • Web and API Enumeration: Discover Swagger, OpenAPI, GraphQL, JavaScript, source map, and legacy endpoints across alive web applications.
  • Security Posture Analysis: Assess HTTP security headers, email authentication controls, vendor fingerprints, subdomain takeover indicators, and exposed cloud storage.
  • Evidence-Backed Triage: Classify observations by severity, preserve evidence references, score endpoint interest, and hand off qualified leads to related security workflows.
  • Use Case: During an authorized bug-bounty engagement, use this Skill to identify an unauthenticated API specification, exposed internal hostnames, weak DMARC policy, and a potentially claimable subdomain without performing exploitation.

Quick Start

Use the web-surface skill to enumerate and prioritize exposed API, endpoint, email-security, vendor, cloud-storage, and documentation findings for an authorized target.

Frequently Asked Questions about web-surface

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I enumerate exposed API endpoints and web applications during authorized reconnaissance?

You can enumerate exposed API endpoints by discovering Swagger, OpenAPI, GraphQL, JavaScript, and source map specifications across alive web applications. This process converts exposed endpoints and infrastructure signals into prioritized reconnaissance leads for authorized security testing.

What is the best way to check for subdomain takeover indicators and weak email security controls?

The best way to check for subdomain takeover indicators and weak email security is to assess HTTP security headers, DMARC policies, and vendor fingerprints. This identifies potentially claimable subdomains and weak email authentication controls without requiring active exploitation.

Can I perform external attack surface management on cloud buckets and public documentation?

Yes, you can perform external attack surface management on exposed cloud storage and public documentation leaks. The workflow systematically finds security weaknesses, infrastructure clues, and exposed vendor products to produce evidence-backed triage findings.

How do I prioritize reconnaissance leads for a bug bounty engagement?

To prioritize reconnaissance leads for a bug bounty engagement, you classify observations by severity, preserve evidence references, and score endpoint interest. This hands off qualified finding candidates to related security workflows for authorized targets.

Does this web reconnaissance approach require active exploitation to find security gaps?

No, this web reconnaissance approach does not require active exploitation to find security gaps. It uses detection-aware probing to identify unauthenticated API specifications, exposed internal hostnames, and weak security postures while outputting structured finding candidates.

What scope and approval controls are needed for web attack surface discovery?

Web attack surface discovery requires explicit scope and approval controls before probing authorized targets. You must maintain evidence IDs for all claims and ensure all endpoint discovery, security posture analysis, and infrastructure signal checks remain within authorized boundaries.