What problem does it solve? Authorized black-box web and API assessments often produce noisy, unverifiable asset lists that mix out-of-scope hosts, stale DNS records, and false positives. This Skill enforces an evidence-gated workflow that turns raw discovery signals into a scoped, attributable attack-surface map with provenance, ownership, status, tech stack, and labels. ## Core Features & Use Cases - Engagement Gating: Requires declared authorization, locked scope, and host/identity/path baselines before any probing begins. - Minimal Safe Validation: Orders checks from low-cost to higher-cost: host availability, soft-404 baseline, homepage/robots/security contacts, browser network capture, then JS/API surface enumeration. - False-Positive Oracles: Treats WAF blocks, captchas, timeouts, and scanner hits as INCONCLUSIVE, and rejects assets lacking reproducible sourcing or current reachability. - Use Case: During an authorized bug-bounty engagement, feed newly discovered in-scope hosts into the workflow to produce a validated asset graph, then route JS/API findings to SPA analysis and stack/CVE findings to vulnerability methodology skills. ## Quick Start Use web2-recon to build an evidence-gated asset map for my authorized in-scope web targets starting from the declared scope baseline.