Cariddi is a Go-based security tool that takes a list of domains, crawls their URLs, and scans for endpoints, secrets, API keys, file extensions, tokens, and errors. It supports configurable concurrency, depth limits, proxy routing, and multiple output formats.
Scanned 6/8/2026
Install via CLI
openskills install agentskillexchange/skills---
name: "Cariddi Domain Crawler and Endpoint Secret Scanner"
slug: "cariddi-domain-crawler-endpoint-secret-scanner"
description: "Cariddi is a Go-based security tool that takes a list of domains, crawls their URLs, and scans for endpoints, secrets, API keys, file extensions, tokens, and errors. It supports configurable concurrency, depth limits, proxy routing, and multiple output formats."
github_stars: 3338
verification: "security_reviewed"
source: "https://github.com/edoardottt/cariddi"
author: "Edoardo Ottavianelli"
category: "Security & Verification"
framework: "Multi-Framework"
tool_ecosystem:
github_repo: "edoardottt/cariddi"
github_stars: 3338
---
# Cariddi Domain Crawler and Endpoint Secret Scanner
Cariddi is a Go-based security tool that takes a list of domains, crawls their URLs, and scans for endpoints, secrets, API keys, file extensions, tokens, and errors. It supports configurable concurrency, depth limits, proxy routing, and multiple output formats.
## Installation
Use the upstream install or setup path that matches your environment:
- brew install cariddi
- go install -v github.com/edoardottt/cariddi/cmd/cariddi@latest
- git clone https://github.com/edoardottt/cariddi.git
- make linux # (to install)
Basic usage or getting-started notes:
- <a href="#usage-">Usage</a> •
- ----------
- #### Homebrew
- Source: https://github.com/edoardottt/cariddi
- Extracted from upstream docs: https://raw.githubusercontent.com/edoardottt/cariddi/HEAD/README.md
## Source
- [Agent Skill Exchange](https://agentskillexchange.com/skills/cariddi-domain-crawler-endpoint-secret-scanner/)
No comments yet. Be the first to comment!
Ultra-compressed communication mode. Cuts token usage ~75% by speaking like caveman while keeping full technical accuracy. Supports intensity levels: lite, full (default), ultra, wenyan-lite, wenyan-full, wenyan-ultra. Use when user says "caveman mode", "talk like caveman", "use caveman", "less tokens", "be brief", or invokes /caveman. Also auto-triggers when token efficiency is requested.