Agent skill

Recon Scope Triage

by elementalsouls in elementalsouls/Claude-BugHunter

Triage ASM/recon output for ownership before testing — separate the target's real assets from namespace-collision noise.

MITAuto-check: notesSecurity

Install Recon Scope Triage

skills CLI
$ npx skills add elementalsouls/Claude-BugHunter --skill recon-scope-triage -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install elementalsouls/Claude-BugHunter recon-scope-triage --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/elementalsouls/Claude-BugHunter.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/recon-scope-triage .claude/skills/recon-scope-triage && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
recon-scope-triage
GitHub stars
4.8k
Token cost
~1.9k tokens
SKILL.md length
811 words
Files
1
Skills in repo
19
Repo updated
First seen
Licence
MIT

At a glance

Triage ASM/recon output for ownership before testing — separate the target's real assets from namespace-collision noise.

  • Works in 2 steps: Wasting the engagement testing/triaging… → Attacking an innocent third party that…
  • Tasks that involve Bug bounty
  • SKILL.md covers When to use this skill, The collision sources (where…, Web "Critical" triage — the… and The triage workflow, plus 3 more sections
  • Calls curl and php

What it does

Recon Scope Triage is an agent skill from elementalsouls/Claude-BugHunter. Triage ASM/recon output for ownership before testing — separate the target's real assets from namespace-collision noise. Automated recon keyword-matches on the brand name, so for any target whose name is a common/dictionary word, the output is dominated by assets belonging to UNRELATED same-named companies (repos, cloud buckets, mobile apps, breach corpora, typosquats). Built from an authorized engagement where an ASM report's "Criticals" were overwhelmingly false positives and the combo/repos/mobile/bucket lists…

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Bug bounty and OSINT. The repository describes itself as: A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patterns curated across 24 core vulnerability classes… The licence is MIT.

When your agent uses it

  • Tasks that involve Bug bounty
  • Tasks that involve OSINT

Example prompts

  • “Criticals”
  • “/recon-scope-triage”

Workflow steps

2 steps, taken from the first numbered list in SKILL.md.

  1. Wasting the engagement testing/triaging assets that aren't the target's.
  2. Attacking an innocent third party that merely shares the name — out of scope, and real harm.

What it can do on your machine

Read from SKILL.md and the folder at commit ec51cd4. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • php

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use curl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Recon Scope Triage loads about 1.9k tokens when it runs. Until then it costs about 175 tokens; SKILL.md has 811 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~175
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:39
    Automated `.env` / `.git` / `actuator` / admin-panel "Criticals" are overwhelmingly **soft-404s**: SPA/framework catch-a
  • NoteMentions a .env fileSKILL.md:42
    ize_download}\n" https://host.target.com/.env
  • NoteMentions a .env fileSKILL.md:48
    tch-all (`.git/config` starts `[core]`; `.env` has `KEY=value`; phpinfo has the XHTML-transitional doctype + `PHP Versio

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from elementalsouls/Claude-BugHunter at commit ec51cd4, republished under its MIT licence (© elementalsouls). 811 words, ~1,867 tokens.

Download SKILL.mdSave it as .claude/skills/recon-scope-triage/SKILL.md (or your agent's skills folder).
name
recon-scope-triage
description
Triage ASM/recon output for ownership before testing — separate the target's real assets from namespace-collision noise. Automated recon keyword-matches on the brand name, so for any target whose name is a common/dictionary word, the output is dominated by assets belonging to UNRELATED same-named companies (repos, cloud buckets, mobile apps, breach corpora, typosquats). Built from an authorized engagement where an ASM report's "Criticals" were overwhelmingly false positives and the combo/repos/mobile/bucket lists were polluted with unrelated same-named orgs. Use at the START of any engagement, immediately on receiving any ASM/recon/OSINT dataset, BEFORE testing anything.
sources
authorized-engagement
report_count
1

When to use this skill

Trigger when:

  • The target brand is a common/dictionary word or shared term (e.g. apex, summit, vertex, nova, core, orbit, pulse, unity…)
  • You receive an ASM report, recon export, breach combo, repo list, bucket list, or mobile-app list to act on
  • A "Critical" count looks implausibly high (hundreds) for the org's size
  • Any asset's ownership is asserted by the tool but not proven

The two failure modes this skill prevents:

  1. Wasting the engagement testing/triaging assets that aren't the target's.
  2. Attacking an innocent third party that merely shares the name — out of scope, and real harm.

Rule: ownership is guilty-until-proven. An asset is the target's only when a concrete ownership signal ties it to the target — never because a scanner's keyword matched.


The collision sources (where keyword-matching lies)

Recon sourceHow it collidesVerify ownership by
GitHub reposSearch matched the brand word in repo name / topic / a stringRepo owner is the org's GH org; commits from org emails; code references the org's real domains/infra. A repo named <word>-backend by a random user = noise.
Cloud buckets (S3/GCS)Bucket names are a global namespace; <word>-static, <word>-data, <word>-public exist for someoneBucket content references the target; bucket name correlates with a confirmed target subdomain (x.target.com ↔ x-public) AND content matches; ACL/owner metadata. Generic content (other-language, other-industry) = not theirs.
Mobile appsStore search matched the brand word in app name / packagePublisher account = the org; package reverse-DNS = an owned domain (com.<owneddomain>.app); dev cert; app calls owned API hosts. Mature ASM tools emit an "apps_accepted=0" / ownership-confidence field — read it.
Breach corpora / combosEmail local-or-domain contains the brand wordExact owned-domain match only (@target.com), not @<word>group.com / @something<word>.com. A different domain that contains the word is a different org.
TyposquatsGenerated permutations of the nameThese are defensive/brand-protection findings, not offensive scope — note and move on.
Stack/forum/paste hitsBrand word in bodyBody references the target's real domain/subdomain/employee/secret. Ownership-confidence < threshold = drop.

Web "Critical" triage — the soft-404 control

Automated .env / .git / actuator / admin-panel "Criticals" are overwhelmingly soft-404s: SPA/framework catch-alls returning HTTP 200 (or 403) for every path. Verify EACH before believing it:

bash
# the "finding"
curl -s -o /tmp/a -w "%{http_code} %{size_download}\n" https://host.target.com/.env
# a junk control on the same host
curl -s -o /tmp/b -w "%{http_code} %{size_download}\n" https://host.target.com/zzz-nonsense-$RANDOM
# identical byte length / body  →  FALSE POSITIVE (catch-all), discard
cmp -s /tmp/a /tmp/b && echo "SOFT-404 false positive" || echo "differs — investigate"

Real exposures have a content-type + signature that differs from the catch-all (.git/config starts [core]; .env has KEY=value; phpinfo has the XHTML-transitional doctype + PHP Version). A physical .php/phpinfo.php that returns a bigger/different body than the junk control is the real-vs-soft-404 tell.


The triage workflow

  1. Confirm the canonical owned-domain set first (the SOW/program domain + its verified subdomains + the verified Entra/Okta/Google tenant brand name). This is your ownership anchor.
  2. For each asset class, apply the verify-by column above. No signal → quarantine, don't test.
  3. Re-baseline the severity counts against only-owned assets. Report the delta — "N Criticals → M after ownership + soft-404 triage" is itself a finding about the ASM program.
  4. Quarantine collisions explicitly (a loot/quarantined_<source>.txt) so it's auditable that you saw them and chose not to target them.
  5. Surface the meta-finding: if the supplied ASM/recon feed is mostly false-positive, that misallocates the owner's remediation budget and buries real risk — write it up (Medium/Strategic).

Show full SKILL.md (308 more words)Show less

Anti-patterns

  • Trusting the tool's "owned" label. Tools keyword-match; they don't prove ownership. Verify.
  • Targeting a same-named third party because it was "in the report." Out of scope + real harm. A combo line user@<word>company.com is a different company's employee.
  • Reporting soft-404s as exposures. Always run the junk-path control.
  • Counting typosquats / missing-headers / brand-collision repos as offensive findings. They're defensive/hygiene/noise — they pad the report and erode credibility.
  • Skipping triage "to save time." Untriaged, you spend the whole engagement on other people's assets and find nothing real.

Why this matters (calibration)

For a target whose brand is a common word, expect the bulk of automated "owned" assets to be collisions:

  • Repos that are unrelated open-source projects (ad-block lists, scrapers, student projects, a different company's SDK) merely containing the word.
  • Mobile apps published by entirely different companies that share the name — banks, credit unions, dating apps, dispensaries, home-care services are all real-world collision categories. (Good ASM tooling will tell you it accepted zero as owned.)
  • Cloud buckets in the global namespace holding some unrelated org's content (other-language documents, demo/sample data, another industry's files).
  • Breach combos full of emails from sibling-named-but-different companies (<word>group.com, <region><word>.com).

On a real engagement against a dictionary-word brand, after clearing this noise the only genuinely-owned high-severity finding was discoverable solely by manual tradecraft (a JS-bundle → API discovery, see hunt-spa-api) — it was nowhere in the hundreds of scanner "Criticals." Triage-first is what made the engagement productive instead of a goose chase.


  • triage-validation — asset-ownership triage (this skill) precedes finding-validity triage (the 7-Question Gate). Ownership first, then validity.
  • redteam-mindset — "aggressive default" means probe every owned live surface; this skill defines which surfaces are owned so persistence isn't wasted on collisions.
  • hunt-spa-api — once an API host passes ownership triage, this is how you test it.
  • offensive-osint / osint-methodology — feed ownership anchors (verified domains, tenant brand, dev accounts) from OSINT into this triage.

© elementalsouls, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/recon-scope-triage of elementalsouls/Claude-BugHunter.

Open the folder on GitHubat commit ec51cd4

Compare with similar skills

Recon Scope Triage next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Recon Scope Triage compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Recon Scope Triage this skillelementalsouls/Claude-BugHunter4.8k—~1.9kAutomated safety check: NotesMIT
Metabigor OSINT Reconj3ssie/metabigor1.8k—~2.4kAutomated safety check: PassMIT
Osint Methodologyelementalsouls/Claude-OSINT2.8k—~8.7kAutomated safety check: NotesMIT
External Recon PlaybookPentesterFlow/agent1.4k—~1.2kAutomated safety check: PassApache-2.0
Web3 Smart Contract Auditawarexone/Agentic-Bug-Hunter5.3k3 repos~4.5kAutomated safety check: PassMIT
Bug Bounty Hunting Methodologyawarexone/Agentic-Bug-Hunter5.3k2 repos~4.7kAutomated safety check: PassMIT

Similar skills

  • Metabigor OSINT Recon

    j3ssie/metabigor

    Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys.

    1.8k GitHub stars~2.4k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Osint Methodology

    elementalsouls/Claude-OSINT

    Comprehensive OSINT methodology for external red-team operations and authorized attack-surface assessments.

    2.8k GitHub stars~8.7k tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • External Recon Playbook

    PentesterFlow/agent

    Maps the attack surface of a web domain you are authorized to test: confirms scope, lists subdomains from public sources, probes live hosts and fingerprints technology.

    1.4k GitHub stars~1.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Web3 Smart Contract Audit

    awarexone/Agentic-Bug-Hunter

    Guides smart contract audits and bounty target selection with ten DeFi bug classes, kill signals, a Foundry PoC template and grep patterns.

    5.3k GitHub starsUsed in 3 repos~4.5k tokens
    SecurityAuto-check passed
  • Bug Bounty Hunting Methodology

    awarexone/Agentic-Bug-Hunter

    Orchestrates a bug bounty session with a 5-phase workflow and a critical-thinking framework covering developer psychology, anomaly detection and What-If experiments.

    5.3k GitHub starsUsed in 2 repos~4.7k tokens
    SecurityAuto-check passed
  • Wooyun Legacy

    tanweai/wooyun-legacy

    WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…

    1.8k GitHub stars~1.9k tokensUpdated 2 mo ago
    SecurityAuto-check passed

More from elementalsouls/Claude-BugHunter

All 19 skills in this repo
  • Hunt Business Logic

    elementalsouls/Claude-BugHunter

    Hunting skill for business logic vulnerabilities. An agent skill from elementalsouls/Claude-BugHunter.

    4.8k GitHub starsUsed in 1 repo~4.4k tokens
    Auto-check passed
  • Hunt API Misconfig

    elementalsouls/Claude-BugHunter

    Hunt API security misconfiguration — mass assignment, prototype pollution, HTTP verb tampering.

    4.8k GitHub stars~4.5k tokensUpdated yesterday
    Auto-check passed
  • Hunt Ato

    elementalsouls/Claude-BugHunter

    Hunt account takeover taxonomy — 9 distinct paths to ATO, plus chains.

    4.8k GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • Hunt Fintech Graphql

    elementalsouls/Claude-BugHunter

    Hunt fintech-specific GraphQL vulnerabilities: money-movement mutations (transfers, redemptions, withdrawals, card top-ups), ledger/balance/portfolio query IDOR, decimal-precision and rounding…

    4.8k GitHub stars~3.5k tokensUpdated yesterday
    Auto-check passed
  • Hunt HTTP Smuggling

    elementalsouls/Claude-BugHunter

    Hunt HTTP request smuggling (CL.TE, TE.CL, H2.CL, H2.TE). An agent skill from elementalsouls/Claude-BugHunter.

    4.8k GitHub stars~1.8k tokensUpdated yesterday
    Auto-check passed
  • Hunt JWT Crypto

    elementalsouls/Claude-BugHunter

    Hunt JWT cryptographic failures — alg:none signature-stripping and RS256→HS256 key-confusion that let an attacker forge a token for any identity (e.g.

    4.8k GitHub stars~2.3k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Recon Scope Triage

What does Recon Scope Triage do?

Triage ASM/recon output for ownership before testing — separate the target's real assets from namespace-collision noise. Recon Scope Triage is an agent skill from elementalsouls/Claude-BugHunter. Triage ASM/recon output for ownership before testing — separate the target's real assets from namespace-collision noise.

When should I use Recon Scope Triage?

Recon Scope Triage fits situations like: tasks that involve Bug bounty; tasks that involve OSINT.

How do I install Recon Scope Triage in Claude Code?

Run `npx skills add elementalsouls/Claude-BugHunter --skill recon-scope-triage -a claude-code`. Or copy the skill folder (skills/recon-scope-triage in elementalsouls/Claude-BugHunter) into .claude/skills/recon-scope-triage in your project. Claude Code loads it when a task matches its description.

How do I install Recon Scope Triage in Codex?

Run `npx skills add elementalsouls/Claude-BugHunter --skill recon-scope-triage -a codex`. Or copy the skill folder (skills/recon-scope-triage in elementalsouls/Claude-BugHunter) into .agents/skills/recon-scope-triage in your project. Codex loads it when a task matches its description.

Can I use Recon Scope Triage in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add elementalsouls/Claude-BugHunter --skill recon-scope-triage -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/recon-scope-triage, .gemini/skills/recon-scope-triage, .github/skills/recon-scope-triage and .opencode/skills/recon-scope-triage in your project.

What does Recon Scope Triage need to run?

Going by SKILL.md and its folder, Recon Scope Triage needs the command-line tools its instructions call (curl and php).

Does Recon Scope Triage access the network?

SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Recon Scope Triage safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Recon Scope Triage use?

Recon Scope Triage is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Recon Scope Triage use?

About 1.9k tokens (SKILL.md is roughly 7.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Recon Scope Triage?

Skills that share tags, products or a category with Recon Scope Triage: Metabigor OSINT Recon (j3ssie/metabigor, 1.8k stars), Osint Methodology (elementalsouls/Claude-OSINT, 2.8k stars), External Recon Playbook (PentesterFlow/agent, 1.4k stars) and Web3 Smart Contract Audit (awarexone/Agentic-Bug-Hunter, 5.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Recon Scope Triage?

elementalsouls (a GitHub user) maintains it in elementalsouls/Claude-BugHunter, which has 4,816 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on October 8, 2026.

Source: elementalsouls/Claude-BugHunter on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.