Install the "external-enumeration" agent skill from https://github.com/forefy/.context/tree/main/skills/hunter-utils/external-enumeration into .claude/skills/external-enumeration/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "external-enumeration", then confirm the skill loads.
Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
skills CLI
$ npx skills add forefy/.context --skill external-enumeration -a codex
Project install goes to .agents/skills/; add -g for ~/.codex/skills/.
Install the "external-enumeration" agent skill from https://github.com/forefy/.context/tree/main/skills/hunter-utils/external-enumeration into .agents/skills/external-enumeration/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "external-enumeration", then confirm the skill loads.
Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add forefy/.context --skill external-enumeration -a cursor
Project install goes to .agents/skills/; add -g for ~/.cursor/skills/.
Install the "external-enumeration" agent skill from https://github.com/forefy/.context/tree/main/skills/hunter-utils/external-enumeration into .cursor/skills/external-enumeration/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "external-enumeration", then confirm the skill loads.
Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
skills CLI
$ npx skills add forefy/.context --skill external-enumeration -a gemini-cli
Project install goes to .agents/skills/; add -g for ~/.gemini/skills/.
Install the "external-enumeration" agent skill from https://github.com/forefy/.context/tree/main/skills/hunter-utils/external-enumeration into .gemini/skills/external-enumeration/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "external-enumeration", then confirm the skill loads.
Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
skills CLI
$ npx skills add forefy/.context --skill external-enumeration -a github-copilot
Project install goes to .agents/skills/; add -g for ~/.copilot/skills/.
Install the "external-enumeration" agent skill from https://github.com/forefy/.context/tree/main/skills/hunter-utils/external-enumeration into .github/skills/external-enumeration/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "external-enumeration", then confirm the skill loads.
GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add forefy/.context --skill external-enumeration -a opencode
OpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
Install the "external-enumeration" agent skill from https://github.com/forefy/.context/tree/main/skills/hunter-utils/external-enumeration into .opencode/skills/external-enumeration/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "external-enumeration", then confirm the skill loads.
OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Facts
Skill name
external-enumeration
GitHub stars
152
Token cost
~3.1k tokens
SKILL.md length
863 words
Files
1
Skills in repo
20
Repo updated
First seen
Licence
MIT
At a glance
Passively map a company's domains, subdomains, DNS ownership, tech stack, and CDNs.
Works in 12 steps: Scope Clarification → Domain Ownership & Attribution → Multi-Source Subdomain Enumeration → …
Recon an external attack surface
SKILL.md covers Phase 0 - Scope Clarification, Phase 1 - Domain Ownership &…, Phase 2 - Multi-Source… and Phase 3 - DNS Resolution &…, plus 9 more sections
Calls curl, python3 and npm; reaches crt.sh and api.hackertarget.com
What it does
External Enumeration is an agent skill from forefy/.context. Passively map a company's domains, subdomains, DNS ownership, tech stack, and CDNs. Use to recon an external attack surface or enumerate subdomains.
Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Threat modeling and Cloud networking. It works with Cloudflare and Microsoft Azure. The repository describes itself as: AI Agent Skills, Goals and Dynamic Workflows for Security Auditing, Pentesting and Research. The licence is MIT.
When your agent uses it
Recon an external attack surface
Enumerate subdomains
Example prompts
“/external-enumeration”
Requirements
Python 3
Node.js
Workflow steps
12 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit c8ff161. It shows what the files ask for, not the result of running them.
Tool permissions
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Runs code
Shell commands in SKILL.md call:
curl
python3
npm
npx
brew
From the folder's file list and the shell code blocks in SKILL.md.
Network
Hosts in commands or code, which the agent is likely to contact:
crt.sh
api.hackertarget.com
web.archive.org
urlscan.io
rapiddns.io
otx.alienvault.com
From URLs in SKILL.md, links to its own repository left out.
Credentials
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Context cost
External Enumeration loads about 3.1k tokens when it runs. Until then it costs about 42 tokens; SKILL.md has 863 words of instructions outside code blocks.
Always· name and description, kept in context so the agent knows when to use it
~42
When it runs· the whole SKILL.md, loaded when a task matches
~3.1k
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
Safety
Auto-check passed
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Download SKILL.mdSave it as .claude/skills/external-enumeration/SKILL.md (or your agent's skills folder).
name
external-enumeration
description
Passively map a company's domains, subdomains, DNS ownership, tech stack, and CDNs. Use to recon an external attack surface or enumerate subdomains.
External Enumeration Skill
You are performing passive external reconnaissance on a target company's domain infrastructure.
Goal: produce a comprehensive, structured map of all domains, subdomains, technology stack, and notable security observations - using only passive/OSINT techniques (no active exploitation).
Phase 0 - Scope Clarification
Ask the user for:
Primary domain(s) to enumerate (e.g. example.com)
Known subsidiaries or related companies (acquisitions, brand names, sister domains)
Output format - markdown report to a file path?
Depth - quick pass (passive DNS only) or deep pass (stealth browser + port scan)?
Phase 1 - Domain Ownership & Attribution
Before enumerating subdomains, confirm what domains are actually owned by the target.
Note: Most domains use privacy protection (e.g. GoDaddy DomainsbyProxy) - registrant names will be hidden. Do NOT rely on registrant names for attribution.
for d in domain1.com domain2.io domain3.net; do
echo -n "$d: "; dig NS $d +short | sort | tr '\n' ' '; echo
done
Identical NS pairs = same DNS account = same owner. This is the strongest passive attribution proof even when WHOIS is privacy-protected.
1.3 MX + TXT Record Cross-Reference
bash
dig MX <domain> +short
dig TXT <domain> +short
Shared *.mail.protection.outlook.com MX = same Microsoft 365 tenant
TXT records reveal: Azure site verifications, Google Workspace, Atlassian, SendGrid
Azure TXT format: MS=ms... or azurewebsites.net subdomain references → same Azure tenant
1.4 Similar-Name Domain Trap
Note: Always verify similar-sounding domains (e.g. target.net, target.co) are actually owned by the target - different registrar or NS pair = likely unrelated squatter. Never assume.
Phase 2 - Multi-Source Subdomain Enumeration
Run all sources in parallel on first pass. crt.sh alone is never sufficient.
2.1 Certificate Transparency (crt.sh)
bash
curl -s "https://crt.sh/?q=%.example.com&output=json" \
| python3 -c "import sys,json; [print(e['name_value']) for e in json.load(sys.stdin)]" \
| tr ',' '\n' | sort -u | grep -v '^\*'
# Resolve all subdomains, identify live ones
while read sub; do
ip=$(dig +short A "$sub" 2>/dev/null | grep -m1 -oP '\d+\.\d+\.\d+\.\d+')
if [ -n "$ip" ]; then
echo "$sub -> $ip"
fi
done < subdomains_unique.txt
Phase 4 - One-Pass Comprehensive Header Harvest
Collect ALL headers in a single pass. Do not come back for a second pass.
bash
collect_headers() {
local sub=$1
local result=$(curl -sk -o /dev/null \
--max-time 10 \
-D - \
-A "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36" \
"https://$sub" 2>/dev/null | head -80)
local status=$(echo "$result" | head -1 | grep -oP '\d{3}')
local ip=$(dig +short A "$sub" 2>/dev/null | grep -m1 -oP '\d+\.\d+\.\d+\.\d+')
python3 -c "
import sys, json
headers_raw = '''$result'''
h = {}
for line in headers_raw.split('\n')[1:]:
if ': ' in line:
k, v = line.split(': ', 1)
h[k.lower().strip()] = v.strip()
print(json.dumps({'subdomain': '$sub', 'status': '$status', 'ip': '$ip', **h}))
"
}
Phase 5 - Technology Identification
5.1 From Server Headers
server value
Technology
cloudflare
Cloudflare WAF/proxy
gunicorn
Python WSGI - direct exposure, no WAF
nginx
Nginx (may be direct or behind CDN)
UploadServer
Google Cloud Storage
AmazonS3
AWS S3 bucket
5.2 From CNAME Chains
bash
dig CNAME <subdomain> +short
CNAME target
Platform
*.hubspot.net
HubSpot (email/link tracking)
*.lmspowered.com
LearnUpon LMS
*.partner-experience.com
Partner portal SaaS
*.pendo.io
Pendo product analytics
*.salesforce.com
Salesforce CRM
*.zendesk.com
Zendesk support
*.freshdesk.com
Freshdesk support
*.atlassian.net
Atlassian (Jira/Confluence)
*.cloudfront.net
AWS CloudFront (if direct CNAME, not leaked via)
*.vercel.app
Vercel hosting
*.netlify.app
Netlify hosting
*.azurewebsites.net
Azure App Service
5.3 From Redirect Targets (location header)
launcher.myapps.microsoft.com → Azure AD SSO (check URL for tenant ID)
x-amz-cf-pop: TLV55-P1 → CloudFront PoP in Tel Aviv
x-cache: Miss from cloudfront → CloudFront active behind CF
x-amz-cf-id: → unique CloudFront request ID
Why it matters: Reveals true backend CDN provider, geographic PoP locations, and hints at origin server region.
Show full SKILL.md (347 more words)Show less
Phase 7 - Cloudflare Bypass (Stealth Browser)
When Cloudflare blocks curl, use stealth Playwright.
Note: Critical package name: Use puppeteer-extra-plugin-stealth - NOT playwright-extra-plugin-stealth (that package does NOT exist and will throw an error).
bash
cd /tmp && mkdir cf-stealth && cd cf-stealth
npm init -y
npm install playwright playwright-extra puppeteer-extra-plugin-stealth
npx playwright install chromium
Don't run on Cloudflare IPs, don't run on WAFs/CDNs protected targets.
Only look for applicative ports, don't overdo the web scan to more than a few strategic port decisions (passive-first approach).
bash
for host in direct-ip-1 direct-ip-2; do
for port in 80 443 8080 8443 3000 4443; do
result=$(curl -sk --max-time 5 -o /dev/null -w "%{http_code}" \
"$([ $port = 443 ] || [ $port = 8443 ] && echo https || echo http)://$host:$port/")
[ "$result" != "000" ] && echo "$host:$port -> HTTP $result"
done
done
Phase 9 - Subsidiary & Acquisition Research
Stealth startups acquired by the target may have no public domain - this is normal.
Search strategy:
"[company name]" acquisition site:crunchbase.com
"[company name]" acquired site:techcrunch.com OR site:businesswire.com
LinkedIn: search target company name → filter by "acquired by" or check leadership history
Check registrant/NS of likely related domains (founder names, product names)
Note: A stealth startup may have: no domain, no Wayback archive, no CT certificates, no passive DNS entries - this is expected, not a gap in enumeration.
Phase 10 - Notable Findings (Auto-Flag)
Always flag these automatically in the report:
Pattern
Flag
access-control-allow-origin: *
Warning - Open CORS - unauthenticated cross-origin requests allowed
External Enumeration next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
System security hardening expertise covering CIS benchmarks, OS hardening for Linux and Windows, container hardening, network hardening, application hardening, database hardening, cloud hardening…
Audits the Safe multisig wallets of DeFi protocols for governance misconfigurations, scoring each against a finding library and producing a severity-ranked report.
Turns a company's domains into likely storage bucket names and checks six cloud providers for publicly readable buckets, for authorized security assessments only.
Passively map a company's domains, subdomains, DNS ownership, tech stack, and CDNs. context. Passively map a company's domains, subdomains, DNS ownership, tech stack, and CDNs.
How do I install External Enumeration in Claude Code?
Run `npx skills add forefy/.context --skill external-enumeration -a claude-code`. Or copy the skill folder (skills/hunter-utils/external-enumeration in forefy/.context) into .claude/skills/external-enumeration in your project. Claude Code loads it when a task matches its description.
How do I install External Enumeration in Codex?
Run `npx skills add forefy/.context --skill external-enumeration -a codex`. Or copy the skill folder (skills/hunter-utils/external-enumeration in forefy/.context) into .agents/skills/external-enumeration in your project. Codex loads it when a task matches its description.
Can I use External Enumeration in Cursor, Gemini CLI or GitHub Copilot?
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add forefy/.context --skill external-enumeration -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/external-enumeration, .gemini/skills/external-enumeration, .github/skills/external-enumeration and .opencode/skills/external-enumeration in your project.
What does External Enumeration need to run?
Going by SKILL.md and its folder, External Enumeration needs the command-line tools its instructions call (curl, python3, npm, npx and brew). Our summary lists: Python 3; Node.js.
Does External Enumeration access the network?
SKILL.md names 6 domains. In commands or code: crt.sh, api.hackertarget.com, web.archive.org, urlscan.io, rapiddns.io and otx.alienvault.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Is External Enumeration safe to install?
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
What licence does External Enumeration use?
External Enumeration is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
How many tokens does External Enumeration use?
About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
What are the alternatives to External Enumeration?
Skills that share tags, products or a category with External Enumeration: Implementing Cloud Waf Rules (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Managing DNS (ancoleman/ai-design-components, 526 stars), Security Hardener (FerroxLabs/wayland, 608 stars) and Azure Firewall (vinayaklatthe/microsoft-security-skills, 175 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Who maintains External Enumeration?
forefy (a GitHub user) maintains it in forefy/.context, which has 152 GitHub stars. The repository holds 20 skills in this directory. The repository was last updated on October 4, 2026.
Source: forefy/.context on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.