Skip to content
Back to skills

Site Reconnaissance

ASecurity

Use when you need to know what a website or web app actually is and does before reviewing or changing it: its framework, routes, audience, accounts, payments, email, analytics, forms, third parties, and deployment. It builds a short evidence-labeled context from the repository, config, and running site without a questionnaire. Do not use it to draft policies, apply fixes, or ask the user questions the repository can answer.

  • 2 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 1, 2026
ai-agentsgonextjsnodedockerapidatabase

Works with

  • api

Security analysis

A100/100

Pro scans all 6 files and shows the line behind each finding

Scanned October 1, 2026

npx -y skills add moh-obaida/ReadyVibe-Skills --skill site-reconnaissance --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Site Reconnaissance?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Site Reconnaissance
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/moh-obaida-site-reconnaissance/badge)](https://www.skillsdirectory.com/skills/moh-obaida-site-reconnaissance)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: site-reconnaissance
description: "Use when you need to know what a website or web app actually is and does before reviewing or changing it: its framework, routes, audience, accounts, payments, email, analytics, forms, third parties, and deployment. It builds a short evidence-labeled context from the repository, config, and running site without a questionnaire. Do not use it to draft policies, apply fixes, or ask the user questions the repository can answer."
license: Apache-2.0
metadata:
  kind: foundation
  compliance-domains: "1"
  helpers: "inspect-metadata"
---

# site-reconnaissance

Every other ReadyVibe skill is only as good as its picture of the product. This skill builds that picture from the artifacts, and writes it down briefly so nobody re-derives it.

## Activate when

- Starting any substantial launch review, or the first time a specialist is invoked on a project.
- The applicable checks depend on facts you do not yet have (is there email? accounts? payments? which markets?).
- Skip it when `.readyvibe/context.md` exists, is recent, and nothing relevant changed. Update rather than redo.

## Inspect

Work from the cheapest, most reliable sources first.

1. **Project shape.** `package.json` (framework, dependencies, scripts), lockfile, framework config (`next.config.*`, `vite.config.*`, `astro.config.*`), deployment files (`vercel.json`, `netlify.toml`, `wrangler.toml`, Dockerfile, CI workflows), README and docs.
2. **Routes and surfaces.** File-based routes (`app/`, `pages/`, `src/routes/`), router config, API routes, server actions. Separate public, authenticated, admin, and utility routes.
3. **Data and services.** Dependencies and imports that imply auth (next-auth, Clerk, Supabase auth, Firebase), payments (Stripe, Paddle, Lemon Squeezy, PayPal), email (Resend, SendGrid, Postmark, Mailchimp), analytics/ads/replay (GA, GTM, Meta Pixel, PostHog, Hotjar, Clarity, Plausible), error monitoring, AI providers, CMS, databases, storage, maps, chat, captcha. Environment templates (`.env.example`) name services; never read secret values from `.env`.
4. **Forms and data.** Every `<form>`, submit handler, and API route: which fields, where they go, whether stored.
5. **Audience and markets.** Copy, currencies, languages/locales, `hreflang`, shipping or pricing regions, legal pages already present, "who is this for" text, age or DOB fields. Only *documented* markets count; a TLD or timezone is a weak hint, not a jurisdiction.
6. **Runtime, when a URL exists.** `node scripts/inspect-metadata.mjs --url <site>` for public structure and hosts; the running site for what actually renders. For what loads and stores, hand off to `cookie-and-storage-audit`.

Do not ask a questionnaire. Ask only when an unresolved fact changes what will be done, at most three questions, and keep working meanwhile. Typical justified questions: "Is this meant to be indexed?", "Which countries do you sell to?", "What is the production URL?".

## Evidence that counts

Label each claim OBSERVED, SOURCE-INDICATED, DECLARED, INFERRED, UNKNOWN, or REVIEW REQUIRED. UNKNOWN is never a pass and never a failure.

- A dependency in `package.json` is SOURCE-INDICATED. It may be unused. Check for an import or a script tag before saying the product "uses Stripe".
- An `.env.example` entry says a service is expected, not that it is live.
- README claims are DECLARED. Treat as leads.
- Do not infer a legal jurisdiction. Record markets as DECLARED (stated) / INFERRED (from a strong documented signal, with the signal) / UNKNOWN.

## May change

Only an optional working note, `.readyvibe/context.md`, which other skills may read but none require. Never product code.

Suggested shape (short, human-readable, each line evidence-labeled):

```
# Launch context (updated <date>)
Product: invoicing app for freelancers  [DECLARED: README]
Stack: Next.js 14 (App Router), Vercel  [OBSERVED: package.json, vercel.json]
Public vs internal: public marketing site + authenticated app under /app  [SOURCE-INDICATED: routes]
Audience/markets: freelancers; English only; markets not documented  [UNKNOWN]
Accounts/auth: yes, Supabase auth  [SOURCE-INDICATED]
Payments: none found  [OBSERVED: no processor imports or scripts]
Email: Resend, transactional only so far; no newsletter form  [SOURCE-INDICATED]
Analytics/ads/cookies: Vercel Analytics; PostHog imported in app/layout.tsx  [SOURCE-INDICATED; runtime not tested]
Forms: waitlist (email), contact (name/email/message)  [OBSERVED]
Third parties: Google Fonts, Stripe.js? (no)  [OBSERVED]
Age/children: no DOB field; adult B2B copy  [OBSERVED]
Indexing intent: marketing pages public, /app private  [DECLARED by user]
Production URL: https://ledgerly.app  [DECLARED]
Open questions: which countries do you sell to?
```

## Must not claim

That a service is live, a market is targeted, or a feature is absent from code alone. "No payments found" means none were found in the places searched (say which).

## Verify

Cross-check two independent sources for anything that will drive a decision (a dependency *and* an import or network request; a route file *and* a live response). Note where you relied on one source.

## Escalate

Contradictions between docs and code, or signs of a regulated domain (health, finance, children, legal, education) or of unusual data (biometrics, precise location): flag for `regulated-domain-triggers` immediately.

## No change is valid when

`.readyvibe/context.md` is already accurate. Say "context unchanged" and do not rewrite it.

Files in this skill

  • SKILL.md5.4 KB
  • scripts/inspect-metadata.mjs23.9 KB
  • scripts/lib/browser.mjs3.3 KB
  • scripts/lib/html.mjs5.8 KB
  • scripts/lib/pages.mjs11.3 KB
  • scripts/lib/report.mjs3 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…