External Recon Playbook
PentesterFlow/agent
Maps the attack surface of a web domain you are authorized to test: confirms scope, lists subdomains from public sources, probes live hosts and fingerprints technology.
Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys.
$ npx skills add j3ssie/metabigor --skill metabigor -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install j3ssie/metabigor metabigor --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/j3ssie/metabigor.git skills-src && mkdir -p .claude/skills && cp -r skills-src/public/skills/metabigor .claude/skills/metabigor && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "metabigor" agent skill from https://github.com/j3ssie/metabigor/tree/main/public/skills/metabigor into .claude/skills/metabigor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "metabigor", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/j3ssie/metabigor/tree/main/public/skills/metabigorType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add j3ssie/metabigor --skill metabigor -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install j3ssie/metabigor metabigor --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/j3ssie/metabigor.git skills-src && mkdir -p .agents/skills && cp -r skills-src/public/skills/metabigor .agents/skills/metabigor && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "metabigor" agent skill from https://github.com/j3ssie/metabigor/tree/main/public/skills/metabigor into .agents/skills/metabigor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "metabigor", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add j3ssie/metabigor --skill metabigor -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install j3ssie/metabigor metabigor --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/j3ssie/metabigor.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/public/skills/metabigor .cursor/skills/metabigor && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "metabigor" agent skill from https://github.com/j3ssie/metabigor/tree/main/public/skills/metabigor into .cursor/skills/metabigor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "metabigor", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/j3ssie/metabigor.git --path public/skills/metabigor--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add j3ssie/metabigor --skill metabigor -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install j3ssie/metabigor metabigor --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/j3ssie/metabigor.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/public/skills/metabigor .gemini/skills/metabigor && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "metabigor" agent skill from https://github.com/j3ssie/metabigor/tree/main/public/skills/metabigor into .gemini/skills/metabigor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "metabigor", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install j3ssie/metabigor metabigorInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add j3ssie/metabigor --skill metabigor -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/j3ssie/metabigor.git skills-src && mkdir -p .github/skills && cp -r skills-src/public/skills/metabigor .github/skills/metabigor && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "metabigor" agent skill from https://github.com/j3ssie/metabigor/tree/main/public/skills/metabigor into .github/skills/metabigor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "metabigor", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add j3ssie/metabigor --skill metabigor -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install j3ssie/metabigor metabigor --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/j3ssie/metabigor.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/public/skills/metabigor .opencode/skills/metabigor && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "metabigor" agent skill from https://github.com/j3ssie/metabigor/tree/main/public/skills/metabigor into .opencode/skills/metabigor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "metabigor", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
metabigorOperates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys.
Metabigor is a command-line OSINT tool, part of the Osmedeus Engine, that maps infrastructure from free sources. The skill covers each subcommand: net for network ranges from an ASN, organization, domain or IP; cert for subdomains from certificate logs; ip for ports and CVEs through Shodan InternetDB; github for secrets and subdomains in public code; cluster for grouping IPs by ASN; related for pivoting through crt.sh, WHOIS and analytics; cdn for spotting CDN and WAF vendors and candidate origins; url for archived URLs and WARC-mined endpoints; and update for the offline databases.
Every command accepts targets in the same four ways, and the merged list is deduplicated. Results go to stdout and logs to stderr, one -f flag picks text, flat, json or csv, the flat format emits the bare primary value so one command feeds the next, and failures exit non-zero so it fits scripts and CI. The net and cluster commands work offline from a bundled database, and the url command optionally reads keys from environment variables only. Reference files hold recipes and details of the url command.
Read from SKILL.md and the folder at commit 5785d65. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
jqFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
twitter.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
VT_API_KEYVIRUSTOTAL_API_KEYINTELX_API_KEYURLSCAN_API_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Metabigor OSINT Recon loads about 2.4k tokens when it runs, and up to ~3.8k if it reads all its reference files. Until then it costs about 167 tokens; SKILL.md has 789 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from j3ssie/metabigor at commit 5785d65, republished under its MIT licence (© j3ssie). 789 words, ~2,388 tokens.
.claude/skills/metabigor/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.CLI-first OSINT tool that maps a target's infrastructure from free sources,
no API keys. Part of the Osmedeus Engine. Every command takes targets the same
four ways and renders through one -f/--format flag, so any command pipes
cleanly into the next.
metabigor net AS13335 # network ranges (CIDRs) behind an ASN
metabigor cert hackerone.com # subdomains from certificate logs
metabigor ip 1.1.1.1 # open ports + CVEs for an IP (free, no key)
metabigor related tesla.com # other domains the target owns
metabigor cdn --exclude -I ips.txt # drop CDN/WAF IPs, keep candidate origins
metabigor url hackerone.com -f flat # every archived URL, ready to pipemetabigor <command> -h is authoritative for the version you have installed.
net/cluster work fully offline from a
bundled database. The url command optionally reads keys from the
environment only (VT_API_KEY/VIRUSTOTAL_API_KEY, INTELX_API_KEY,
URLSCAN_API_KEY) — never from a flag or config file.metabigor cert x.com | other-tool always works. Progress is quiet by
default; add -v for step-by-step lines.-f/--format text|flat|json|csv covers every command.
There are no per-command format flags.flat format emits the bare primary value so one
command's output is the next command's input.&&, set -e, and CI.Identical on every command; the merged list is deduplicated.
metabigor cert example.com # as an argument
metabigor cert example.com tesla.com # several arguments
metabigor cert -i example.com # with -i (use when a target looks like a flag)
metabigor cert -I domains.txt # from a file, one per line (# comments ignored)
cat domains.txt | metabigor cert # on stdinStdin is read only when no target was given another way, so
metabigor net AS13335 never blocks inside a script or CI job.
| I need to… | Use |
|---|---|
| Find CIDRs announced by an ASN | metabigor net AS13335 |
| Find which ASN owns an IP | metabigor net 1.1.1.1 --detail |
| Find ranges by company name | metabigor net --org Cloudflare |
| Query live BGP sources, not the local DB | metabigor net --live tesla.com |
| Enumerate subdomains from cert logs | metabigor cert hackerone.com |
| Cert search by organization | metabigor cert "HackerOne Inc" |
Strip *. from wildcard cert entries | metabigor cert example.com --clean |
| Cert IDs, issuers, validity dates | metabigor cert example.com --detail |
| Ports / hostnames / CVEs for an IP | metabigor ip 1.1.1.1 |
| Enrich a whole CIDR | metabigor ip 1.1.1.0/28 |
| Search public GitHub code (grep.app) | metabigor github hackerone.com |
| Pull only subdomains out of code matches | metabigor github tesla.com --subs |
| Show the matching code lines | metabigor github "api_key=" --detail |
| Group IPs by owning ASN | metabigor cluster -I ips.txt |
| Pivot to related domains (all sources) | metabigor related hackerone.com |
| Pivot via specific sources | metabigor related tesla.com --sources crt,whois |
| Collect archived URLs (keyless sources) | metabigor url hackerone.com |
| Scope URL collection to one host | metabigor url blog.hackerone.com --no-subs |
| Detect CDN/WAF vendor for an IP | metabigor cdn 1.1.1.1 |
| Drop CDN/WAF IPs, keep origins | metabigor cdn --exclude -I ips.txt |
| Keep only CDN/WAF-protected IPs | metabigor cdn --only -I ips.txt |
| Refresh the offline ASN/country DBs | metabigor update |
| Print / install these agent skills | metabigor skills get --full |
-f/--format on every command. Default is text.
| Format | Flag | What you get | Use it for |
|---|---|---|---|
| Text (default) | -f text | Readable `a | b |
| Flat | -f flat | The bare primary value, one per line | Piping into other tools |
| JSON | -f json | One JSON object per line | jq, automation |
| CSV | -f csv | Rows behind one header | Spreadsheets, reports |
metabigor ip 1.1.1.0/28 # 1.1.1.1 | 80,443 | one.one.one.one
metabigor ip 1.1.1.0/28 -f flat # 1.1.1.1:80
metabigor ip 1.1.1.0/28 -f json | jq . # {"ip":"1.1.1.1","ports":[80,443],...}
metabigor ip 1.1.1.0/28 -f csv -o ports.csv-o <file> also writes results to a file (overwrite; --append to add).
Things -h alone won't make obvious.
net auto-detects the target type; override with --asn, --ip,
--domain, or --org (mutually exclusive). --detail adds ASN / org /
country columns. --live swaps the offline DB for live BGP sources
(bgp.he.net) — slower, but current.cert prints a plain domain list by default. --detail gives the grouped
certificate view (IDs, issuers, dates); --clean strips *.; --wildcard
keeps only wildcard entries. Feed it into a resolver: metabigor cert t.com | dnsx -silent.ip uses Shodan InternetDB (free, no key). IPs it knows nothing about are
skipped; pass --all to keep them. CIDRs expand to hosts.github needs Chrome/Chromium (grep.app blocks plain HTTP clients).
Searches run one at a time regardless of -c to respect grep.app's rate
limit. --subs returns subdomains only; --detail shows code; --pages N
goes deeper.cluster groups IPs/CIDRs by owning ASN, largest cluster first. Fully
offline.related sources: crt (crt.sh), whois (viewdns.info reverse WHOIS),
analytics (shared Google Analytics / Tag Manager IDs), or all (default).
Results are deduped across sources and tagged with the first source that found
each.cdn classifies IPs by CDN/WAF vendor. --exclude drops protected IPs
(leaving candidate origins); --only keeps just the protected ones. The two
are mutually exclusive.url includes subdomains by default (queries *.target) — the single
biggest lever on volume; --no-subs narrows it. GhostArchive is mined:
its WARCs expose sub-request URLs (XHR/JSON endpoints) that no CDX index
lists. Filters are off by default. See references/url-command.md.update refreshes both the IP-to-ASN and IP-to-country databases in
~/.metabigor. A copy ships with the binary and unpacks on first use, so this
is only needed to pick up newer routing data. -i, --input string Target to look up (also accepts arguments or stdin)
-I, --input-file string File of targets, one per line (use - for stdin)
-o, --output string Also write results to this file
-f, --format string Output format: text, json, csv, flat (default "text")
--append Append to the output file instead of overwriting it
-c, --concurrency int Number of parallel workers (default 10)
-t, --timeout int Request timeout in seconds (default 40)
--retry int Retries per failed request (default 3)
--proxy string Upstream proxy, e.g. http://127.0.0.1:8080
-v, --verbose Show step-by-step progress
-q, --quiet Show results and errors only
--debug Show HTTP traffic and internal traces (implies --verbose)
--no-color Disable colored log outputThe point of the flat format: chain commands into a workflow.
# ASN -> ranges -> live hosts with ports
metabigor net AS13335 -f flat | metabigor ip -f flat
# domain -> related domains -> their subdomains
metabigor related tesla.com -f flat | metabigor cert
# resolve subdomains, then split CDN from candidate origins
metabigor cert tesla.com | dnsx -silent -resp-only | metabigor cdn --exclude
# collect archived URLs and probe them
metabigor url tesla.com -f flat | httpx -silentMore multi-step workflows: references/recipes.md.
metabigor <command> -h # authoritative flags for your installed version
metabigor version # version, build date, commit
metabigor skills get --full # print this skill and every reference© j3ssie, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (references) in public/skills/metabigor of j3ssie/metabigor.
Open the folder on GitHubat commit 5785d65
Metabigor OSINT Recon next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Metabigor OSINT Recon this skillj3ssie/metabigor | 1.8k | — | ~2.4k | Automated safety check: Pass | MIT | |
| External Recon PlaybookPentesterFlow/agent | 1.4k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | |
| Vulnerability Lookupptn1411/skill | 220 | — | ~1.1k | Automated safety check: Pass | None | |
| Wooyun Legacytanweai/wooyun-legacy | 1.8k | — | ~1.9k | Automated safety check: Pass | Custom licence | |
| Client Request Signature Reversalawarexone/Agentic-Bug-Hunter | 5.3k | — | ~4.7k | Automated safety check: Pass | MIT | |
| Web3 Bug Bounty AI Toolstradecatlabs/vibe-coding-cn | 17k | 2 repos | ~3.9k | Automated safety check: Warn | MIT |
PentesterFlow/agent
Maps the attack surface of a web domain you are authorized to test: confirms scope, lists subdomains from public sources, probes live hosts and fingerprints technology.
ptn1411/skill
Multi-source threat intelligence and vulnerability lookup. An agent skill from ptn1411/skill.
tanweai/wooyun-legacy
WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…
awarexone/Agentic-Bug-Hunter
Recovers a client-side request signature or anti-bot token just far enough to replay blocked requests in bug bounty testing, starting from a captured packet.
tradecatlabs/vibe-coding-cn
A selection guide to AI-driven tools for Web3 bug bounty work, from autonomous web pentesters to smart contract bug finders, with notes on authorization.
samugit83/redamon
Adding partial-recon support for a tool: running a single pipeline phase on demand from the workflow graph, reading its inputs from the existing Neo4j graph and merging results back.
Works with
Categories
Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys. Metabigor is a command-line OSINT tool, part of the Osmedeus Engine, that maps infrastructure from free sources.sh, WHOIS and analytics; cdn for spotting CDN and WAF vendors and candidate origins; url for archived URLs and WARC-mined endpoints; and update for the offline databases.
Metabigor OSINT Recon fits situations like: mapping the network ranges behind an ASN, organization or domain; enumerating subdomains of a domain from certificate logs; finding likely origin servers behind a CDN or WAF; chaining several recon commands into one pipeline.
Run `npx skills add j3ssie/metabigor --skill metabigor -a claude-code`. Or copy the skill folder (public/skills/metabigor in j3ssie/metabigor) into .claude/skills/metabigor in your project. Claude Code loads it when a task matches its description.
Run `npx skills add j3ssie/metabigor --skill metabigor -a codex`. Or copy the skill folder (public/skills/metabigor in j3ssie/metabigor) into .agents/skills/metabigor in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add j3ssie/metabigor --skill metabigor -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/metabigor, .gemini/skills/metabigor, .github/skills/metabigor and .opencode/skills/metabigor in your project.
Going by SKILL.md and its folder, Metabigor OSINT Recon needs the command-line tools its instructions call (jq) and credentials named VT_API_KEY, VIRUSTOTAL_API_KEY, INTELX_API_KEY and URLSCAN_API_KEY. Our summary lists: The metabigor CLI.
SKILL.md names 1 domain. As links in the text: twitter.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Metabigor OSINT Recon is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.4k tokens (SKILL.md is roughly 9.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.4k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Metabigor OSINT Recon: External Recon Playbook (PentesterFlow/agent, 1.4k stars), Vulnerability Lookup (ptn1411/skill, 220 stars), Wooyun Legacy (tanweai/wooyun-legacy, 1.8k stars) and Client Request Signature Reversal (awarexone/Agentic-Bug-Hunter, 5.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
j3ssie (a GitHub user) maintains it in j3ssie/metabigor, which has 1,849 GitHub stars. The repository was last updated on August 8, 2026.
Source: j3ssie/metabigor on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.