Agent skill

Wiki Recon

by Encod3d-Sec in Encod3d-Sec/TORCH

External recon and OSINT pipeline - subdomain enum, live host discovery, URL crawl, JS analysis, nuclei scan.

MITAuto-check passedSecurity

Install Wiki Recon

skills CLI
$ npx skills add Encod3d-Sec/TORCH --skill wiki-recon -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Encod3d-Sec/TORCH wiki-recon --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/workflow/wiki-recon .claude/skills/wiki-recon && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
wiki-recon
GitHub stars
329
Token cost
~1.3k tokens
SKILL.md length
401 words
Files
1
Skills in repo
35
Repo updated
First seen
Licence
MIT

At a glance

External recon and OSINT pipeline - subdomain enum, live host discovery, URL crawl, JS analysis, nuclei scan.

  • Starting recon on any target
  • SKILL.md covers Phase 0: Wiki Query (MANDATORY), Scope Check, Recon Pipeline and Output to Attack-surface.md, plus 1 more section
  • Calls curl, jq and bash; reaches crt.sh
  • Tasks that involve Threat modeling

What it does

Wiki Recon is an agent skill from Encod3d-Sec/TORCH. External recon and OSINT pipeline - subdomain enum, live host discovery, URL crawl, JS analysis, nuclei scan. Outputs to Attack-surface.md and scope/. Queries wiki before each phase. Use when starting recon on any target.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Threat modeling, LLM wikis and OSINT. The repository describes itself as: Karpathy LLM based claude harness for PenetrationTesting / Bugbounty using obsidian. The licence is MIT.

When your agent uses it

  • Starting recon on any target
  • Tasks that involve Threat modeling
  • Tasks that involve LLM wikis

Example prompts

  • “/wiki-recon”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit d21b6c9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • jq
    • bash
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • crt.sh

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Wiki Recon loads about 1.3k tokens when it runs. Until then it costs about 58 tokens; SKILL.md has 401 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~58
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Encod3d-Sec/TORCH at commit d21b6c9, republished under its MIT licence (© Encod3d-Sec). 401 words, ~1,335 tokens.

Download SKILL.mdSave it as .claude/skills/wiki-recon/SKILL.md (or your agent's skills folder).
name
wiki-recon
description
External recon and OSINT pipeline - subdomain enum, live host discovery, URL crawl, JS analysis, nuclei scan. Outputs to Attack-surface.md and scope/. Queries wiki before each phase. Use when starting recon on any target.

Wiki-Recon: External Recon Pipeline

Phase 0: Wiki Query (MANDATORY)

qmd_query "recon subdomain enumeration" via wiki-search MCP -> read matching pages.
qmd_query "OSINT external attack surface" -> apply known techniques.

If no matching page: proceed. Do not block on missing wiki coverage. Dorks to find exposed/vulnerable assets: wiki/cheatsheets/recon-dorks.md; attack paths once in: wiki/cheatsheets/attack-chains.md.

Scope Check

  • Confirm target domain(s) are in scope
  • Read Attack-surface.md - skip hosts already fully documented
  • Read Deadends.md - skip recon paths already exhausted

Recon Pipeline

Tool-first: subfinder/assetfinder for subdomains, httpx for live-host probing, katana/gau for URLs, ffuf for content discovery, nuclei for templated checks. The crt.sh curl below is the one hand request kept (a passive source with no tool wrapper); everywhere else lean on the tool, not a curl loop.

Stage 1: Subdomain Discovery
bash
TARGET="target.com"
RECON_DIR="poc/recon/$TARGET"
mkdir -p $RECON_DIR

# Passive sources
curl -s "https://crt.sh/?q=%.${TARGET}&output=json" \
  | jq -r '.[].name_value' | sed 's/\*\.//g' | sort -u > $RECON_DIR/subs.txt

subfinder -d $TARGET -silent | tee -a $RECON_DIR/subs.txt
assetfinder --subs-only $TARGET | tee -a $RECON_DIR/subs.txt
sort -u $RECON_DIR/subs.txt -o $RECON_DIR/subs.txt
Stage 2: Live Host Discovery
bash
cat $RECON_DIR/subs.txt | dnsx -silent | \
  httpx -silent -status-code -title -tech-detect | tee $RECON_DIR/live.txt

On any TLS host from Stage 2, dump the cert SANs early; a hidden vhost none of the above discovers can be listed only in the Subject Alternative Name, see [[cdn-waf-bypass]].

Stage 3: URL Crawl + Historical
bash
cat $RECON_DIR/live.txt | awk '{print $1}' | \
  katana -d 3 -jc -kf all -silent | tee $RECON_DIR/urls.txt
echo $TARGET | waybackurls | tee -a $RECON_DIR/urls.txt
gau $TARGET --subs | tee -a $RECON_DIR/urls.txt
sort -u $RECON_DIR/urls.txt -o $RECON_DIR/urls.txt
Stage 4: Nuclei Scan
bash
nuclei -l $RECON_DIR/live.txt -t ~/nuclei-templates/ \
  -severity critical,high,medium -o $RECON_DIR/nuclei.txt
Stage 5: Attack Surface Triage
bash
# Content discovery on live hosts: OUR high-signal list first (non-obvious routes the crawl missed)
ffuf -c -u https://HOST/FUZZ -w scripts/wordlists/harness-paths.txt -e .php,.py -mc 200,301,302,401,403 -ac

# High-value URL patterns
cat $RECON_DIR/urls.txt | grep -E "\?.*=" | grep -E "url=|redirect=|src=|dest=|fetch=" > $RECON_DIR/ssrf_candidates.txt
cat $RECON_DIR/urls.txt | grep -E "\?.*=" | grep -E "id=|user_id=|order_id=|doc_id=" > $RECON_DIR/idor_candidates.txt
cat $RECON_DIR/urls.txt | grep -E "graphql|/gql|/graph" > $RECON_DIR/graphql_candidates.txt
cat $RECON_DIR/urls.txt | grep -E "upload|import|parse|convert|preview|render" > $RECON_DIR/upload_candidates.txt

# JS secret scanning
cat $RECON_DIR/urls.txt | grep "\.js$" | \
  xargs -I {} curl -sk {} | grep -E "(api_key|apikey|secret|token|password|credential).*['\"][A-Za-z0-9+/]{20,}" \
  > $RECON_DIR/js_secrets.txt

READ each app .js / inline <script> / button onclick / href END-TO-END, do not stop at the grep. The secret-scan above only surfaces hardcoded keys; the initial attack vector (an AJAX handler POSTing to an undocumented endpoint, a commented route, a hidden param) hides in code the grep filters out. Open every first-party bundle and read it top to bottom, grep only to LOCATE inside a large file, then read the block. A page that looks like a static template is often a dynamic app whose whole endpoint map lives in one JS file.

Show full SKILL.md (162 more words)Show less

Run each scan in its own tmux tab on the VM (root, persistent), one tab per target: bash scripts/vm-scan.sh <eng> <target> '<scan>' (multi-web target -> <target>-web-<ip-or-domain>). Capture a live/finished tab with Skill(screenshot) --tmux <eng>:<tab> (use the @NN id or sanitized tab name it prints). Capture standalone tool output (nmap service surface, ffuf/feroxbuster hits, nuclei findings) as terminal-card PNGs via Skill(screenshot) --term for the Attack-surface evidence.

Output to Attack-surface.md

For each discovered live host, add a row to the target's Attack-surface.md:

markdown
| sub.target.com | 1.2.3.4 | [status] | - | [finding or notes] |

Add newly discovered hosts to scope/ IP/domain lists.

Record recon progress in targets/<eng>/Approach.md Phase 1 items.

If nuclei finds CRITICAL or HIGH severity issues: create a FIND-XXX entry immediately.

Distill to wiki (when confirmed): if a novel subdomain takeover or recon-bypass technique is found, stage a GENERIC wiki candidate now (no client host): python3 scripts/wiki-stage.py --kind technique --slug <slug> --target-page techniques/osint/web-attack-surface.md. Promote later via scripts/wiki-promote.py.

Context tools

<!-- auto-wired: documented tools to reach for; do not hand-roll -->
  • [[amass]]
  • [[subfinder]]
  • [[dnsx]]
  • [[gau]]
  • [[gowitness]]
  • [[wiki/tools/httpx]]
  • [[katana]]

© Encod3d-Sec, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/workflow/wiki-recon of Encod3d-Sec/TORCH.

Open the folder on GitHubat commit d21b6c9

Compare with similar skills

Wiki Recon next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Wiki Recon compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Wiki Recon this skillEncod3d-Sec/TORCH329—~1.3kAutomated safety check: PassMIT
Osint Methodologyelementalsouls/Claude-OSINT2.8k—~8.7kAutomated safety check: NotesMIT
Analysing Attacktsale/awesome-dfir-skills323—~1.4kAutomated safety check: PassApache-2.0
Performing Reconnaissancetrilwu/secskills157—~3.1kAutomated safety check: NotesMIT
Implementing Attack Surface Managementmukul975/Anthropic-Cybersecurity-Skills34k—~1.8kAutomated safety check: PassApache-2.0
Recon Osinthypnguyen1209/offensive-claude388—~2.2kAutomated safety check: PassMIT

Similar skills

  • Osint Methodology

    elementalsouls/Claude-OSINT

    Comprehensive OSINT methodology for external red-team operations and authorized attack-surface assessments.

    2.8k GitHub stars~8.7k tokensUpdated today
    SecurityAuto-check: notes
  • Analysing Attack

    tsale/awesome-dfir-skills

    Analyse Mitre ATT&CK tactics, techniques and sub-techniques.

    323 GitHub stars~1.4k tokensUpdated 4 mo ago
    SecurityAuto-check passed
  • Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access.

    157 GitHub stars~3.1k tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • Implementing Attack Surface Management

    mukul975/Anthropic-Cybersecurity-Skills

    Implements external attack surface management (EASM) using Shodan, Censys, and ProjectDiscovery tools (subfinder, httpx, nuclei) for asset discovery, subdomain enumeration, service fingerprinting…

    34k GitHub stars~1.8k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Recon Osint

    hypnguyen1209/offensive-claude

    A skill your agent uses when mapping a target's external attack surface or gathering OSINT — subdomain enumeration, attack-surface mapping (httpx/katana/JS secrets), subdomain takeover…

    388 GitHub stars~2.2k tokensUpdated 12 days ago
    SecurityAuto-check passed
  • Produce cyber threat intelligence by pivoting on indicators to find related infrastructure, tracking actors and campaigns, enriching and contextualizing IOCs, applying attribution discipline and…

    157 GitHub stars~4.4k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from Encod3d-Sec/TORCH

All 35 skills in this repo
  • Runs a bug-bounty engagement through a script that tracks the current pass, builds a board of rows from recon and prints the next required action each turn.

    329 GitHub stars~1.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Checks that the bb, pt and ctf workflow driver is set up correctly on a machine: vault content, skill symlinks, hooks, imports and a live smoke test, with fixes for failures.

    329 GitHub stars~611 tokensUpdated 1 mo ago
    Auto-check passed
  • Opens a visible Chromium window on a Kali VM so an operator can complete a manual login or CAPTCHA while the agent watches and acts through the chrome-devtools MCP.

    329 GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • CTF Campaign Driver

    Encod3d-Sec/TORCH

    Runs a capture-the-flag box from first scan to root with a driver script that tracks progress and prints the next action each turn.

    329 GitHub stars~1.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Decides when a main pentesting agent should hand a fully-specified, mechanical exploit-compile or privilege-escalation step to a cheaper sub-agent, and how to specify that handoff safely.

    329 GitHub stars~1.6k tokensUpdated 1 mo ago
    Auto-check: notes
  • Adaptive Web Fuzzing

    Encod3d-Sec/TORCH

    Adaptive web fuzzing for pentests, bug bounty and CTF work: picks the smallest suitable SecLists wordlist per target surface and calibrates filters against soft-404 responses.

    329 GitHub stars~1.3k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Wiki Recon

What does Wiki Recon do?

External recon and OSINT pipeline - subdomain enum, live host discovery, URL crawl, JS analysis, nuclei scan. Wiki Recon is an agent skill from Encod3d-Sec/TORCH. External recon and OSINT pipeline - subdomain enum, live host discovery, URL crawl, JS analysis, nuclei scan.

When should I use Wiki Recon?

Wiki Recon fits situations like: starting recon on any target; tasks that involve Threat modeling; tasks that involve LLM wikis.

How do I install Wiki Recon in Claude Code?

Run `npx skills add Encod3d-Sec/TORCH --skill wiki-recon -a claude-code`. Or copy the skill folder (skills/workflow/wiki-recon in Encod3d-Sec/TORCH) into .claude/skills/wiki-recon in your project. Claude Code loads it when a task matches its description.

How do I install Wiki Recon in Codex?

Run `npx skills add Encod3d-Sec/TORCH --skill wiki-recon -a codex`. Or copy the skill folder (skills/workflow/wiki-recon in Encod3d-Sec/TORCH) into .agents/skills/wiki-recon in your project. Codex loads it when a task matches its description.

Can I use Wiki Recon in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Encod3d-Sec/TORCH --skill wiki-recon -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/wiki-recon, .gemini/skills/wiki-recon, .github/skills/wiki-recon and .opencode/skills/wiki-recon in your project.

What does Wiki Recon need to run?

Going by SKILL.md and its folder, Wiki Recon needs the command-line tools its instructions call (curl, jq, bash and python3). Our summary lists: Python 3.

Does Wiki Recon access the network?

SKILL.md names 1 domain. In commands or code: crt.sh; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Wiki Recon safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Wiki Recon use?

Wiki Recon is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Wiki Recon use?

About 1.3k tokens (SKILL.md is roughly 5.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Wiki Recon?

Skills that share tags, products or a category with Wiki Recon: Osint Methodology (elementalsouls/Claude-OSINT, 2.8k stars), Analysing Attack (tsale/awesome-dfir-skills, 323 stars), Performing Reconnaissance (trilwu/secskills, 157 stars) and Implementing Attack Surface Management (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Wiki Recon?

Encod3d-Sec (a GitHub user) maintains it in Encod3d-Sec/TORCH, which has 329 GitHub stars. The repository holds 35 skills in this directory. The repository was last updated on September 1, 2026.

Source: Encod3d-Sec/TORCH on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.