{"repo":"uphiago/recon-skills","free":true,"listed":false,"github":"https://github.com/uphiago/recon-skills","clone":"git clone https://github.com/uphiago/recon-skills.git","description":"Recon & pentest skill pack. CORS, XSS, SQLi, SSRF, RCE, WordPress, MCP, cloud, subdomain takeover, and more. Field-tested. MIT. Full write-up at hiago.sh","language":"Python","stars":1174,"topics":["bug-bounty","cloud-security","firebase-hacking","hermes-agent","jwt-attacks","offensive-security","penetration-testing","reconnaissance","red-team","security-automation"],"license":"MIT","category":"security-tools","readme_excerpt":"Recon Skills A curated pack of security skills for external reconnaissance, web applications, APIs, authentication, vulnerability validation, attack-path analysis, and reporting. These skills are for authorized security testing only. Only test targets you own or have explicit written permission to test. Blog & research : hiago.sh - Pentest Playbook, field notes, and tooling. What Is Included The catalog is primarily focused on external web security: - subdomain, DNS, port, HTTP, and technology discovery; - route, parameter, JavaScript, source-map, and API mapping; - authentication, authorization, session, OAuth, SAML, and MFA testing; - web vulnerability and framework-specific validation; - cloud, identity, container, and exposed-infrastructure pivots; - evidence review, attack-path analysis, and reporting. Each skill owns a focused objective and documents the prerequisites, procedure, pitfalls, verification criteria, and related techniques needed for that objective. Older skills are being migrated incrementally to the complete quality baseline. Catalog Using the Pack Clone the repository and locate the skills that match the observed surface: For a broad external web assessment, useful entry points are redteam/web2-recon , recon/subdomain-enumeration , recon/web-enumeration , and redteam/bb-methodology . Add vulnerability or platform skills only when discovery produces a relevant signal. Set a writable output location before running examples: Commands assume standard Linux to","default_branch":null,"files":null,"tree":[],"storefront":"/r/uphiago","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/uphiago/recon-skills/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}