Agent skill

Recon Attack Surface

by criptogus in criptogus/agent-evolve-network

Plans and runs authorized reconnaissance to enumerate a target's external attack surface (DNS, subdomains, ports, web tech) and produces a prioritized report.

CC-BY-SA-4.0Auto-check passedSecurity

Install Recon Attack Surface

skills CLI
$ npx skills add criptogus/agent-evolve-network --skill recon-attack-surface -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install criptogus/agent-evolve-network recon-attack-surface --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/criptogus/agent-evolve-network.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/recon-attack-surface .claude/skills/recon-attack-surface && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
recon-attack-surface
GitHub stars
288
Token cost
~1.2k tokens
SKILL.md length
246 words
Files
1
Skills in repo
107
Repo updated
First seen
Licence
CC-BY-SA-4.0

At a glance

Plans and runs authorized reconnaissance to enumerate a target's external attack surface (DNS, subdomains, ports, web tech) and produces a prioritized report.

  • The user asks for recon & attack surface mapper work
  • SKILL.md covers Instructions, Always, Never and Input / output contract, plus 2 more sections
  • Calls npx
  • Tasks that involve Threat modeling

What it does

Recon Attack Surface is an agent skill from criptogus/agent-evolve-network. Plans and runs authorized reconnaissance to enumerate a target's external attack surface (DNS, subdomains, ports, web tech) and produces a prioritized report. Use when the user asks for recon & attack surface mapper work, or mentions recon, attack, surface.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Threat modeling and Bug bounty. The licence is CC-BY-SA-4.0.

When your agent uses it

  • The user asks for recon & attack surface mapper work
  • Tasks that involve Threat modeling
  • Tasks that involve Bug bounty

Example prompts

  • “Use the recon-attack-surface skill to plan and runs authorized reconnaissance to enumerate a target's external attack surface (DNS, subdomains…”
  • “/recon-attack-surface”

Requirements

  • Node.js

What it can do on your machine

Read from SKILL.md and the folder at commit d19b920. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • superagentskill.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Recon Attack Surface loads about 1.2k tokens when it runs. Until then it costs about 70 tokens; SKILL.md has 246 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~70
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from criptogus/agent-evolve-network at commit d19b920, republished under its CC-BY-SA-4.0 licence (© criptogus). 246 words, ~1,156 tokens.

Download SKILL.mdSave it as .claude/skills/recon-attack-surface/SKILL.md (or your agent's skills folder).
name
recon-attack-surface
description
Plans and runs authorized reconnaissance to enumerate a target's external attack surface (DNS, subdomains, ports, web tech) and produces a prioritized report. Use when the user asks for recon & attack surface mapper work, or mentions recon, attack, surface.
version
0.1.0
license
CC-BY-SA-4.0
homepage
https://superagentskill.com/marketplace/recon-attack-surface
source
Super Agent Skill (SAK)

Recon & Attack Surface Mapper

Use for authorized pentests, bug-bounty programs and CTFs where the engagement scope clearly permits active probing. Builds a structured plan, suggests safe command sequences (subfinder/amass, dnsx, naabu, httpx, nuclei) and turns raw output into a ranked attack-surface map. Do NOT use against assets the operator has not been authorized to test.

Instructions

You are an authorized red-team analyst. Before producing any commands, restate the in-scope assets and assumed authorization in one paragraph. If scope is missing or unclear, ask for it and stop. Then produce: (1) a passive recon plan (no traffic to target), (2) an active recon plan with rate-limit and noise notes, (3) a prioritized findings table (asset, signal, risk, next step). Never fabricate scan output. Never output exploit payloads or post-exploitation steps in this skill.

Always

  • Reconfirm authorization before suggesting active probes.
  • Annotate every active step with rate-limit and detection-risk notes.
  • Separate passive vs active phases.

Never

  • Recommend exploits, payloads, or post-exploitation actions.
  • Produce commands targeting assets outside the stated scope.
  • Fabricate scan output or invent vulnerabilities.

Input / output contract

Input:

json
{
  "type": "object",
  "properties": {
    "target": {
      "type": "string",
      "description": "root domain, IP range or org name"
    },
    "scope": {
      "type": "string",
      "description": "explicit in-scope assets and rules of engagement"
    },
    "authorization": {
      "type": "string",
      "description": "who authorized the test and when"
    }
  },
  "required": [
    "target",
    "scope",
    "authorization"
  ]
}

Output:

json
{
  "type": "object",
  "properties": {
    "plan_markdown": {
      "type": "string"
    },
    "findings_table": {
      "type": "array"
    }
  },
  "required": [
    "plan_markdown"
  ]
}

Examples

Bug-bounty scope

Input:

target: example.com
scope: "*.example.com, no .gov subdomains, no DoS, max 10 rps"
authorization: "HackerOne program, signed brief 2026-04-12"

Expected output:

## Authorization recap
Authorized via HackerOne brief dated 2026-04-12. In scope: *.example.com excluding .gov subdomains. Rate cap: 10 rps. No DoS.
## Passive recon
- crt.sh + Subfinder for subdomain discovery
- PassiveTotal / SecurityTrails lookups
## Active recon (≤10 rps)
- dnsx resolution sweep, then naabu top-1000 ports, then httpx fingerprint
## Prioritized findings
| Asset | Signal | Risk | Next step |
Internal pentest engagement

Input:

target: 10.20.0.0/16
scope: "Internal corporate network excluding 10.20.99.0/24 (legal). No exploitation, max 50 pps."
authorization: "Signed SOW with Acme Corp, engagement window 2026-05-13 to 2026-05-17"

Expected output:

## Authorization recap
Authorized via signed SOW dated 2026-05-13. Scope: 10.20.0.0/16 minus 10.20.99.0/24. Rate cap: 50 pps. No exploitation; recon and fingerprint only.
## Passive recon
- DHCP / DNS audit from provided collection files
- Pull CMDB / asset inventory if available
## Active recon (≤50 pps)
- `nmap -sn -T2 --max-rate 50 10.20.0.0/16` for liveness
- `naabu -rate 50 -top-ports 100` against live hosts
- `httpx -silent -title -tech-detect` against web ports
## Prioritized findings
| Asset | Signal | Risk | Next step |
| 10.20.4.17 | Exposed `:445` SMBv1 banner | High | Verify CVE-2017-0144 patch level via patch records |
| 10.20.7.10 | Default Tomcat /manager page | Medium | Confirm credentials are not default; document |

Trust & telemetry

This skill is graded on the Super Agent Skill network: format, substance and adversarial (prompt-injection) testing produce a public Trust Score.

Reinstall or update with npx skills update, or pull the live graded version with npx super-agent install recon-attack-surface.

© criptogus, CC-BY-SA-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/recon-attack-surface of criptogus/agent-evolve-network.

Open the folder on GitHubat commit d19b920

Compare with similar skills

Recon Attack Surface next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Recon Attack Surface compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Recon Attack Surface this skillcriptogus/agent-evolve-network288—~1.2kAutomated safety check: PassCC-BY-SA-4.0
Osint Methodologyelementalsouls/Claude-OSINT2.8k—~8.7kAutomated safety check: NotesMIT
Security Specialistfabricioctelles/skills106—~2.8kAutomated safety check: PassApache-2.0
Web2 Reconawarexone/Agentic-Bug-Hunter5.3k2 repos~6.4kAutomated safety check: WarnMIT
Audit Context Buildingtrailofbits/skills7.4k—~996Automated safety check: PassCC-BY-SA-4.0
Reconbriiirussell/cybersecurity-skills413—~1.1kAutomated safety check: NotesMIT

Similar skills

  • Osint Methodology

    elementalsouls/Claude-OSINT

    Comprehensive OSINT methodology for external red-team operations and authorized attack-surface assessments.

    2.8k GitHub stars~8.7k tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • Security Specialist

    fabricioctelles/skills

    Runs security audits on codebases — full scans, diff reviews, threat models, vulnerability triage, remediation guidance, and finding tracking.

    106 GitHub stars~2.8k tokensUpdated 3 days ago
    SecurityAuto-check passed
  • Web2 Recon

    awarexone/Agentic-Bug-Hunter

    Web2 recon pipeline — subdomain enumeration (subfinder, Chaos API, assetfinder), live host discovery (dnsx, httpx), URL crawling (katana, waybackurls, gau), directory fuzzing (ffuf), JS analysis…

    5.3k GitHub starsUsed in 2 repos~6.4k tokens
    SecurityAuto-check: warnings
  • Audit Context Building

    trailofbits/skills

    Official

    Understand a codebase before looking for bugs in it - what each function assumes, what it guarantees, and what it depends on elsewhere.

    7.4k GitHub stars~996 tokensUpdated today
    SecurityAuto-check passed
  • Recon

    briiirussell/cybersecurity-skills

    Perform structured reconnaissance and attack surface enumeration for authorized penetration tests, CTF challenges, and bug bounty programs.

    413 GitHub stars~1.1k tokensUpdated 4 mo ago
    SecurityAuto-check: notes
  • Reconnaissance

    transilienceai/communitytools

    Domain assessment and web application mapping - subdomain discovery, port scanning, endpoint enumeration, API discovery, and attack surface analysis.

    562 GitHub stars~1.4k tokensUpdated 2 mo ago
    SecurityAuto-check passed

More from criptogus/agent-evolve-network

All 107 skills in this repo
  • Brand Research

    criptogus/agent-evolve-network

    Kickoff research for a brand you haven't worked on before — web research, existing-ad analysis from the Meta Ad Library, editorial-grammar profiling, sourced + AI-generated brand assets, hook/CTA…

    288 GitHub stars~3.9k tokensUpdated 28 days ago
    Auto-check passed
  • Create Apple Notes Video Ad

    criptogus/agent-evolve-network

    Produce a 9:16 social-native ad recreating the iPhone Apple Notes typing experience — the note begins with 1–2 visible lines, then progressively types additional paragraphs character-by-character…

    288 GitHub stars~4.9k tokensUpdated 28 days ago
    Auto-check passed
  • Create Chatgpt Video Ad

    criptogus/agent-evolve-network

    Produce a 9:16 social-native ad that recreates a ChatGPT mobile chat — user types in the composer with the iOS keyboard visible, taps send, keyboard slides down, header right-cluster swaps…

    288 GitHub stars~5k tokensUpdated 28 days ago
    Auto-check passed
  • Create Imessage Video Ad

    criptogus/agent-evolve-network

    Produce a 9:16 social-native ad that recreates an iMessage conversation reveal — bubbles pop in over time, composer types char-by-char, real Apple iMessage SFX hit on every send/receive, music bed…

    288 GitHub stars~7.4k tokensUpdated 28 days ago
    Auto-check passed
  • Cloud Misconfig Auditor

    criptogus/agent-evolve-network

    Audits AWS, GCP and Azure environments (and matching IaC) for excessive permissions, public exposure, weak encryption defaults and missing logging.

    288 GitHub stars~965 tokensUpdated 28 days ago
    Auto-check passed
  • Cloudflare Workers Expert

    criptogus/agent-evolve-network

    Builds and debugs Cloudflare Workers, Durable Objects, KV, R2, D1, and Queues with edge-correct patterns.

    288 GitHub stars~619 tokensUpdated 28 days ago
    Auto-check passed

Categories

Questions about Recon Attack Surface

What does Recon Attack Surface do?

Plans and runs authorized reconnaissance to enumerate a target's external attack surface (DNS, subdomains, ports, web tech) and produces a prioritized report. Recon Attack Surface is an agent skill from criptogus/agent-evolve-network. Plans and runs authorized reconnaissance to enumerate a target's external attack surface (DNS, subdomains, ports, web tech) and produces a prioritized report.

When should I use Recon Attack Surface?

Recon Attack Surface fits situations like: the user asks for recon & attack surface mapper work; tasks that involve Threat modeling; tasks that involve Bug bounty.

How do I install Recon Attack Surface in Claude Code?

Run `npx skills add criptogus/agent-evolve-network --skill recon-attack-surface -a claude-code`. Or copy the skill folder (skills/recon-attack-surface in criptogus/agent-evolve-network) into .claude/skills/recon-attack-surface in your project. Claude Code loads it when a task matches its description.

How do I install Recon Attack Surface in Codex?

Run `npx skills add criptogus/agent-evolve-network --skill recon-attack-surface -a codex`. Or copy the skill folder (skills/recon-attack-surface in criptogus/agent-evolve-network) into .agents/skills/recon-attack-surface in your project. Codex loads it when a task matches its description.

Can I use Recon Attack Surface in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add criptogus/agent-evolve-network --skill recon-attack-surface -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/recon-attack-surface, .gemini/skills/recon-attack-surface, .github/skills/recon-attack-surface and .opencode/skills/recon-attack-surface in your project.

What does Recon Attack Surface need to run?

Going by SKILL.md and its folder, Recon Attack Surface needs the command-line tools its instructions call (npx). Our summary lists: Node.js.

Does Recon Attack Surface access the network?

SKILL.md names 1 domain. As links in the text: superagentskill.com. This is read from the text; nothing was executed.

Is Recon Attack Surface safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Recon Attack Surface use?

Recon Attack Surface is published under the CC-BY-SA-4.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Recon Attack Surface use?

About 1.2k tokens (SKILL.md is roughly 4.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Recon Attack Surface?

Skills that share tags, products or a category with Recon Attack Surface: Osint Methodology (elementalsouls/Claude-OSINT, 2.8k stars), Security Specialist (fabricioctelles/skills, 106 stars), Web2 Recon (awarexone/Agentic-Bug-Hunter, 5.3k stars) and Audit Context Building (trailofbits/skills, 7.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Recon Attack Surface?

criptogus (a GitHub user) maintains it in criptogus/agent-evolve-network, which has 288 GitHub stars. The repository holds 107 skills in this directory. The repository was last updated on September 9, 2026.

Source: criptogus/agent-evolve-network on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.