Run scope-bounded reconnaissance for a penetration test: enumerate the authorized attack surface (hosts, domains, services, technologies, exposure) and organize it for testing. Use at the start of an engagement, strictly within the agreed scope.
Scanned 9/19/2026
npx -y skills add jassics/awesome-claude-security --skill recon --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Recon?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/jassics-recon)More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.
---
name: recon
description: >-
Run scope-bounded reconnaissance for a penetration test: enumerate the
authorized attack surface (hosts, domains, services, technologies, exposure)
and organize it for testing. Use at the start of an engagement, strictly within
the agreed scope.
---
# Goal
A clear, organized attack-surface map for the **in-scope** targets, ready to drive
methodology-based testing — with everything tied back to the rules of engagement.
# Prerequisites
- **Authorization and explicit scope** (in-scope hosts/domains/IPs, exclusions,
testing window, rules of engagement). Do not enumerate anything out of scope.
# Steps
1. **Confirm scope** first. Record what's in/out and any constraints (rate limits,
no-touch systems, allowed techniques).
2. **Passive recon** — public/OSINT footprint: domains, subdomains, IP ranges,
technologies, exposed services, leaked info. Prefer the `osint` plugin if
installed.
3. **Active enumeration** (only if authorized) — live hosts, open ports/services,
versions, web endpoints, and tech fingerprinting, respecting rate limits.
4. **Organize the surface** — group by asset/zone; note the technology per target
so the right domain methodology applies (web → `web-app-security`, network →
`network-security`, cloud → `cloud-security`).
5. **Map it** — optionally produce an attack-surface mindmap or architecture view
(`security-diagramming`).
# Output
An attack-surface inventory: asset · type · service/tech · exposure · in-scope? ·
notes, plus a prioritized list of where to begin testing. Findings later flow to
`security-reporting`.
# Notes
Stay strictly within scope; log what you touched for the report's methodology
section. This skill organizes the surface — the per-technology testing lives in
the domain plugins.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!