Agent skill

Web2 Recon

by Gabson0x in Gabson0x/bountyforge

Web2 recon pipeline — subdomain enum, URL crawling, JS analysis, temp emails, directory fuzzing.

No licenceAuto-check passedSecurity

Install Web2 Recon

skills CLI
$ npx skills add Gabson0x/bountyforge --skill web2-recon -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Gabson0x/bountyforge web2-recon --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Gabson0x/bountyforge.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/web2-recon .claude/skills/web2-recon && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
web2-recon
GitHub stars
442
Token cost
~1.6k tokens
SKILL.md length
230 words
Files
1
Skills in repo
6
Repo updated
First seen
Licence
None found

At a glance

Web2 recon pipeline — subdomain enum, URL crawling, JS analysis, temp emails, directory fuzzing.

  • Tasks that involve Fuzzing
  • SKILL.md covers TEMP EMAIL SETUP (Essential…, STANDARD RECON PIPELINE, TRUST BOUNDARY DISCOVERY and JS ANALYSIS — Where Hidden…, plus 4 more sections
  • Calls curl and jq; reaches api.mail.tm and crt.sh; needs CHAOS_API_KEY

What it does

Web2 Recon is an agent skill from Gabson0x/bountyforge. Web2 recon pipeline — subdomain enum, URL crawling, JS analysis, temp emails, directory fuzzing. Trust-first asset discovery.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Fuzzing. The repository describes itself as: all round pentest skill.

When your agent uses it

  • Tasks that involve Fuzzing

Example prompts

  • “/web2-recon”

Requirements

  • A credential in CHAOS_API_KEY

What it can do on your machine

Read from SKILL.md and the folder at commit 068399d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • api.mail.tm
    • crt.sh
    • dns.projectdiscovery.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • CHAOS_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Web2 Recon loads about 1.6k tokens when it runs. Until then it costs about 34 tokens; SKILL.md has 230 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~34
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 230 words (~1,582 tokens).

“Map the attack surface before hunting. Every endpoint is a trust boundary. Find them all.”

— opening of SKILL.md by Gabson0x
name
web2-recon

Read the full SKILL.md on GitHub

Files

Just SKILL.md in skills/web2-recon of Gabson0x/bountyforge.

Open the folder on GitHubat commit 068399d

Compare with similar skills

Web2 Recon next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Web2 Recon compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Web2 Recon this skillGabson0x/bountyforge442—~1.6kAutomated safety check: PassNone
Fizzpashov/skills1.2k2 repos~11kAutomated safety check: PassMIT
Fizz Syncpashov/skills1.2k2 repos~3.9kAutomated safety check: PassMIT
Research FuzzerARA-Labs/Agent-Native-Research-Artifact692—~2.4kAutomated safety check: PassMIT
Vuln Researchtanweai/xianzhi-research185—~847Automated safety check: PassNone
Binary Reverse Engineering Audittihanyin/REx-skill108—~5.1kAutomated safety check: PassMIT

Similar skills

  • Fizz

    pashov/skills

    Generate Echidna/Medusa-compatible Solidity fuzz suites from Foundry or Hardhat projects.

    1.2k GitHub starsUsed in 2 repos~11k tokens
    SecurityAuto-check passed
  • Fizz Sync

    pashov/skills

    Reconcile an existing Fizz harness with a changed source tree.

    1.2k GitHub starsUsed in 2 repos~3.9k tokens
    SecurityAuto-check passed
  • Research Fuzzer

    ARA-Labs/Agent-Native-Research-Artifact

    Treat an open-ended investigation the way a fuzzer treats a program.

    692 GitHub stars~2.4k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Vuln Research

    tanweai/xianzhi-research

    安全研究元思考方法论 - 从先知社区5600+篇安全文档中提炼的漏洞挖掘方法论框架. An agent skill from tanweai/xianzhi-research.

    185 GitHub stars~847 tokensUpdated 8 mo ago
    SecurityAuto-check passed
  • Guides evidence-first reverse engineering of compiled programs to find and prove defects, from triage and decompilation to fuzzing, patch diffing and firmware.

    108 GitHub stars~5.1k tokensUpdated 15 days ago
    SecurityAuto-check passed
  • Harness Design Fuzzing

    provos/ironcurtain

    Reference vocabulary for designing instrumented harnesses that drive vulnerability discovery — design classes (trigger-driven vs coverage-driven), tiered scope (T1 isolated function / T2…

    612 GitHub stars~5.7k tokensUpdated 2 days ago
    SecurityAuto-check passed

More from Gabson0x/bountyforge

  • Solidity Auditor

    Gabson0x/bountyforge

    Security audit of Solidity code while you develop. An agent skill from Gabson0x/bountyforge.

    442 GitHub stars~3.7k tokensUpdated 22 days ago
    Auto-check passed
  • Hackenproof Triage Marketplace

    Gabson0x/bountyforge

    HackenProof bug bounty triage workflow for Claude Code plugin marketplace operations.

    442 GitHub stars~1.2k tokensUpdated 22 days ago
    Auto-check passed
  • Security Arsenal

    Gabson0x/bountyforge

    Security payloads, bypass tables, wordlists, gf pattern names, always-rejected bug list, conditionally-valid-with-chain table, temp email creation scripts, XXE/deserialization/host header injection…

    442 GitHub stars~8.5k tokensUpdated 22 days ago
    Auto-check: warnings
  • Web2 Vuln Classes

    Gabson0x/bountyforge

    Complete reference for 28 web2 bug classes with root causes, detection patterns, bypass tables, exploit techniques, and real paid examples.

    442 GitHub stars~11k tokensUpdated 22 days ago
    Auto-check: warnings
  • Code Sleuth

    Gabson0x/bountyforge

    Analyze EVM smart contracts for storage-safety vulnerabilities that can cause persistent state updates to be lost, overwritten, misdirected, or to collide across proxy or upgrade boundaries.

    442 GitHub stars~1.5k tokensUpdated 22 days ago
    Auto-check passed

Categories

Questions about Web2 Recon

What does Web2 Recon do?

Web2 recon pipeline — subdomain enum, URL crawling, JS analysis, temp emails, directory fuzzing. Web2 Recon is an agent skill from Gabson0x/bountyforge. Web2 recon pipeline — subdomain enum, URL crawling, JS analysis, temp emails, directory fuzzing.

When should I use Web2 Recon?

Web2 Recon fits situations like: tasks that involve Fuzzing.

How do I install Web2 Recon in Claude Code?

Run `npx skills add Gabson0x/bountyforge --skill web2-recon -a claude-code`. Or copy the skill folder (skills/web2-recon in Gabson0x/bountyforge) into .claude/skills/web2-recon in your project. Claude Code loads it when a task matches its description.

How do I install Web2 Recon in Codex?

Run `npx skills add Gabson0x/bountyforge --skill web2-recon -a codex`. Or copy the skill folder (skills/web2-recon in Gabson0x/bountyforge) into .agents/skills/web2-recon in your project. Codex loads it when a task matches its description.

Can I use Web2 Recon in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Gabson0x/bountyforge --skill web2-recon -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/web2-recon, .gemini/skills/web2-recon, .github/skills/web2-recon and .opencode/skills/web2-recon in your project.

What does Web2 Recon need to run?

Going by SKILL.md and its folder, Web2 Recon needs the command-line tools its instructions call (curl and jq) and credentials named CHAOS_API_KEY. Our summary lists: A credential in CHAOS_API_KEY.

Does Web2 Recon access the network?

SKILL.md names 3 domains. In commands or code: api.mail.tm, crt.sh and dns.projectdiscovery.io; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Web2 Recon safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Web2 Recon use?

No licence was found for Web2 Recon or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Web2 Recon use?

About 1.6k tokens (SKILL.md is roughly 6.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Web2 Recon?

Skills that share tags, products or a category with Web2 Recon: Fizz (pashov/skills, 1.2k stars), Fizz Sync (pashov/skills, 1.2k stars), Research Fuzzer (ARA-Labs/Agent-Native-Research-Artifact, 692 stars) and Vuln Research (tanweai/xianzhi-research, 185 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Web2 Recon?

Gabson0x (a GitHub user) maintains it in Gabson0x/bountyforge, which has 442 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on September 16, 2026.

Source: Gabson0x/bountyforge on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.