Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Stack Fingerprint Stinger

ASecurity

Landing-page-only stack and render-mode fingerprinting (React/Vite, Next.js, SvelteKit, WordPress, Shopify, Magento). Writes target-profile.json every later Drone reads.

85 stars
0 votes
0 copies
0 views
Added 9/27/2026
ai-agentsgoreactnextjsgitsecuritydocumentation

Works with

claude codecursor

Security Analysis

A100/100

Pro scans all 10 files and shows the line behind each finding

Scanned 9/27/2026

$npx -y skills add legioncodeinc/vibe-coding-tools --skill stack-fingerprint-stinger --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Stack Fingerprint Stinger?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Stack Fingerprint Stinger
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/legioncodeinc-stack-fingerprint-stinger/badge)](https://www.skillsdirectory.com/skills/legioncodeinc-stack-fingerprint-stinger)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: "stack-fingerprint-stinger"
description: "Landing-page-only stack and render-mode fingerprinting (React/Vite, Next.js, SvelteKit, WordPress, Shopify, Magento). Writes target-profile.json every later Drone reads."
license: AGPL-3.0-or-later
compatibility: "Claude Code, Cursor, ChatGPT Codex, Claude Cowork."
metadata:
  hive-tier: stinger
  hive-drone: stack-fingerprint-wasp-drone
  research-window: 2026-08-18
  primary-surface: external-website-audit
---

# Stack Fingerprint Stinger

> **Forge status:** stages 1-6 complete (Topic, Research, Distillation, References, Guides, final
> Skill/Drone authorship). Stage 7 (Register: pest-controller-suit registration and cross-harness deploy)
> has not run yet.

## Purpose

Equips **stack-fingerprint-wasp-drone**, wave W1a of every Website Auditor by Legion Code Inc.
engagement, to classify the audited site's technology stack and render mode from the landing page
alone, no crawl required, and write the one shared-workspace file (`_shared/target-profile.json`)
every later Drone reads instead of re-detecting anything itself. Full scope and acceptance criteria:
[prd-003-stack-fingerprint](../../library/requirements/backlog/prd-003-stack-fingerprint/prd-003-stack-fingerprint-index.md).

Every factual claim this skill makes traces to a downloaded primary source in
`references/research/raw/` or to this pair's PRD/the build plan; anywhere the archive runs thin
(React+Vite, SvelteKit specifically versus Svelte generally, Magento, and the render-mode comparison
heuristic itself all have no dedicated source), that gap is named explicitly rather than smoothed
into an unstated guess. See `references/research/distilled-stack-fingerprint.md` section 8 and
`references/fingerprint-signature-table.md`.

## When to use this skill

- Wave W1a of every audit run, right after `audit-intake-wasp-drone` scaffolds the workspace, in
  parallel with `vendor-inventory-wasp-drone` (wave W1b)
- Determining crawl strategy before `site-crawler-wasp-drone` starts (wave W4), by writing the
  `platform_guide` pointer it reads
- Re-fingerprinting after a site migration is suspected mid-engagement

## When not to use

- Crawling beyond the landing page and its directly linked static assets, that is
  `site-crawler-wasp-drone`'s job, and only after this Stinger has written `target-profile.json`
- Enumerating third-party vendors/scripts, that is `vendor-inventory-stinger`'s job (its sibling
  wave, not this one)
- Judging the stack choice as good or bad, this Stinger classifies, it does not evaluate

## Procedure

1. Read `00-intake/` for the target URL. Do not ask the user for it again.
2. Fetch the landing page once (single-request channel: HTML, headers, cookies) per
   `guides/01-fetch-and-collect-signals.md`, and perform the one permitted headless-browser load for
   render-mode comparison.
3. Run `shared/scripts/fingerprint.py` against the captured evidence to classify `stack` and
   `rendering` per `guides/02-signature-matching.md` and `guides/03-render-mode-detection.md`. Apply
   the precision-over-recall discipline: match only vendor asset URLs, header names, cookie names,
   or generator tags, never free-text keywords.
4. If nothing matches, report `stack: unknown` with the raw signals attached, per PRD-003 AC-2.
   Never force an unrecognized site into the nearest known category.
5. Write `_shared/target-profile.json` and `01-recon/stack-fingerprint.md` from the same run, per
   `guides/04-write-target-profile-and-report.md`. Set `platform_guide` to the exact build-plan-
   section-6 guide path `site-crawler-wasp-drone` should load next, or `null` if `stack` is
   `unknown`.

## References map

- `references/fingerprint-signature-table.md`, load when applying or extending the signature table,
  or verifying a classification's grounding (researched vs. judgment call)
- `references/templates/target-profile.template.json`, load when writing `_shared/target-profile.json`
- `references/templates/stack-fingerprint-report-template.md`, load when writing
  `01-recon/stack-fingerprint.md`
- `references/research/distilled-stack-fingerprint.md`, load when a domain claim needs verification
  or this Stinger's coverage gaps need checking before making a claim
- `references/research/raw/`, load when tracing a distilled claim back to its primary source
- `references/scripts/README.md` and `shared/scripts/fingerprint.py`, load/run for the deterministic
  matcher that drives steps 3-4 of the procedure above

## Related drones and stingers

- [stack-fingerprint-wasp-drone](../../agents/stack-fingerprint-wasp-drone.md) - this Stinger's
  paired Drone
- [vendor-inventory-stinger](../vendor-inventory-stinger) - runs in parallel, wave W1b; both read
  `00-intake/`, only vendor-inventory also reads this Stinger's `target-profile.json` for
  render-mode context
- [site-crawler-stinger](../site-crawler-stinger) - wave W4, reads this Stinger's
  `target-profile.json` to select its platform-specific crawl strategy without re-detecting anything
- [audit-intake-stinger](../audit-intake-stinger) - wave W0, scaffolds the workspace this Stinger
  reads `00-intake/` from
- [seo-aeo-stinger](../seo-aeo-stinger) - internal-repo SEO/AEO reference; consult for standard
  definitions this external audit's technical-seo pair also relies on

## Critical Directive

- You must read all files and context contained within your skill.
- In the event your core knowledge does not provide sufficient guidance you must make every attempt to search the internet, related knowledge base documentation files, and other available resources to supplement your knowledge prior to proceeding with your task.
- Additional related skills can be found here:
  - [vendor-inventory-stinger](../vendor-inventory-stinger) - parallel wave-W1 sibling; consult when a signal you find looks more like a vendor/tag than a platform/framework signature

## Ship Gate

Ship Gate removed: stack-fingerprint-stinger performs a read-only external website audit and writes
its output into the audited customer's `www.<domain>-audit/` workspace, not into this repository. It
never produces a commit inside this repo as part of its own operation, so the Ship Gate
(security-stinger, then quality-stinger, then github-repo-health-stinger) does not apply to this
pair's runtime procedure. This is separate from the fact that changes to this plugin's own source
(this file included) still go through this repository's normal Ship Gate before being committed, per
the build plan's own development process, that gate governs building the plugin, not what the
plugin does when it runs.

Attribution

legioncodeinclegioncodeinc
View sourceSee grades on GitHubMore from legioncodeinc →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698461 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →