What problem does it solve?
This Skill eliminates the hours of manual, error-prone work involved in web2 reconnaissance for penetration testing and bug bounty engagements, ensuring no attack surface is missed from incomplete subdomain enumeration, URL crawling, or JavaScript analysis.
Core Features & Use Cases
- End-to-End Recon Pipeline: Automates passive subdomain enumeration (crt.sh, Chaos API, subfinder, assetfinder), live host detection, URL crawling (katana, waybackurls, gau), directory fuzzing, and JavaScript secret and endpoint extraction.
- Attack Surface Triage: Uses pattern matching with gf and custom greps to quickly identify high-value targets like API endpoints, authentication paths, and file upload features.
- Use Case: For a new bug bounty target, this Skill maps all assets, identifies 10+ high-priority endpoints, and flags potential CORS, IDOR, and XSS candidates in under 30 minutes, cutting initial recon time from hours to minutes.
Quick Start
Use the web2-recon skill to run a full asset discovery and attack surface mapping workflow on the target example.com, returning a prioritized list of subdomains, live hosts, URLs, and high-value endpoints for vulnerability hunting.