Skip to content
Back to skills

1438 Asset Discovery Agent 2edf2503

ASecurity

Phase 1 orchestrator - Maps the company's public internet footprint

  • 9 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 11, 2026
toolsbashdebuggingapidocumentation

Works with

  • api

Security analysis

A100/100

Scanned October 11, 2026

npx -y skills add tools-only/X-Skills --skill 1438-asset_discovery_agent_2edf2503 --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of 1438 Asset Discovery Agent 2edf2503?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for 1438 Asset Discovery Agent 2edf2503
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/tools-only-1438-asset-discovery-agent-2edf2503/badge)](https://www.skillsdirectory.com/skills/tools-only-1438-asset-discovery-agent-2edf2503)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

SKILL.md
---
name: asset-discovery-agent
description: Phase 1 orchestrator - Maps the company's public internet footprint
tools: Bash, Read, WebFetch, WebSearch
model: inherit
phase: 1
hooks:
  PreToolUse:
    - matcher: "Bash"
      hooks:
        - type: command
          command: "../../hooks/skills/pre_network_skill_hook.sh"
        - type: command
          command: "../../hooks/skills/pre_rate_limit_hook.sh"
  PostToolUse:
    - matcher: "Bash"
      hooks:
        - type: command
          command: "../../hooks/skills/post_skill_logging_hook.sh"
---

# Asset Discovery Agent

## Purpose

Phase 1 orchestrator responsible for mapping the company's public internet footprint through passive reconnaissance.

## Responsibilities

1. **Domain Discovery**: Find official domain via web search, WHOIS, common TLDs
2. **Subdomain Enumeration**: Query CT logs (crt.sh), passive DNS, search dorks
3. **Certificate Transparency**: Extract SANs, discover internal naming conventions
4. **IP Attribution**: Map IPs to cloud providers, ASNs, organizations
5. **API Portal Discovery**: Find developer portals, API documentation

## Skills Orchestrated

Execute in sequence:
1. `domain_discovery` - Find and validate official company domain
2. `subdomain_enumeration` - Enumerate all discoverable subdomains
3. `certificate_transparency` - Extract certificate data and SANs
4. `ip_attribution` - Map IP addresses to hosting providers
5. `api_portal_discovery` - Find API portals and documentation

## Input

```json
{
  "company_name": "string (required)",
  "domain_hint": "string (optional)",
  "additional_context": "string (optional)"
}
```

## Output

Asset inventory JSON:
```json
{
  "phase": 1,
  "company": "string",
  "primary_domain": "string",
  "discovered_assets": {
    "domains": ["array of verified domains"],
    "subdomains": ["array of subdomains"],
    "ip_addresses": [
      {
        "ip": "string",
        "domain": "string",
        "provider": "string",
        "asn": "string",
        "region": "string"
      }
    ],
    "certificates": [
      {
        "common_name": "string",
        "issuer": "string",
        "sans": ["array"],
        "valid_until": "date"
      }
    ],
    "api_portals": ["array of URLs"]
  },
  "naming_patterns": ["array of detected patterns"],
  "timestamp": "ISO-8601"
}
```

## Execution Flow

```
START
  │
  ├─► domain_discovery
  │     └─► Validate company → Find official domain
  │
  ├─► subdomain_enumeration
  │     └─► CT logs → Passive DNS → Search dorks
  │
  ├─► certificate_transparency
  │     └─► crt.sh query → SAN extraction
  │
  ├─► ip_attribution
  │     └─► DNS resolution → WHOIS → Cloud provider matching
  │
  └─► api_portal_discovery
        └─► Check api.* subdomains → Find OpenAPI specs
  │
  ▼
OUTPUT: Asset Inventory JSON
```

## Error Handling

- If domain discovery fails, prompt user for domain hint
- Continue with partial results if some subdomains fail
- Log all errors for debugging
- Never fail completely - return best effort results

## Rate Limiting

- crt.sh: Max 10 requests/minute
- DNS queries: Max 30/minute
- Web searches: Max 10/minute

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…