Agent skill

External Recon Playbook

by PentesterFlow in PentesterFlow/agent

Maps the attack surface of a web domain you are authorized to test: confirms scope, lists subdomains from public sources, probes live hosts and fingerprints technology.

Apache-2.0Auto-check passedSecurity

Install External Recon Playbook

skills CLI
$ npx skills add PentesterFlow/agent --skill recon -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install PentesterFlow/agent recon --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/PentesterFlow/agent.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/recon .claude/skills/recon && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
recon
GitHub stars
1.4k
Token cost
~1.2k tokens
SKILL.md length
406 words
Files
1
Skills in repo
5
Repo updated
First seen
Licence
Apache-2.0

At a glance

Maps the attack surface of a web domain you are authorized to test: confirms scope, lists subdomains from public sources, probes live hosts and fingerprints technology.

  • Works in 5 steps: Confirm scope → Passive subdomain enumeration with curl → Liveness + tech fingerprinting with curl → …
  • Mapping the attack surface of a root domain you have permission to test
  • SKILL.md covers 1. Confirm scope, 2. Passive subdomain…, 3. Liveness + tech… and 4. Content discovery with curl…, plus 1 more section
  • Calls curl and jq; reaches crt.sh and otx.alienvault.com

What it does

The skill starts by restating the apex domain and asking you to confirm it is in scope, noting any out-of-scope subdomains or paths. It stays narrow, with no IP-range scans and no third-party assets, and it defaults to curl and the built-in http tool rather than specialized scanners such as subfinder, httpx, ffuf or gobuster unless you ask for them.

Passive subdomain enumeration pulls from certificate transparency logs through crt.sh, checking that the body is valid JSON and retrying with backoff because the service is flaky, then adds AlienVault OTX passive DNS and saves the deduplicated list under a recon folder for the apex. Each candidate then gets a single GET request to capture status, title and headers such as server and x-powered-by. Real hostnames must replace placeholders before any command runs. Content discovery is listed too, but the excerpt was cut off before it.

When your agent uses it

  • Mapping the attack surface of a root domain you have permission to test
  • Listing subdomains from certificate transparency logs without extra tools
  • Checking which discovered hosts are live and what they run
  • Preparing the recon stage of a bug bounty or pentest engagement

Example prompts

  • “Run recon on example.com, which is in scope for our authorized pentest.”
  • “Enumerate subdomains for our staging apex using only curl and certificate transparency data.”
  • “Probe the hosts in recon/example.com/subs.txt and summarize status codes and server headers.”

Requirements

  • Authorization to test the target domain
  • curl and jq, with network access to public CT log and passive DNS sources
  • Pre-approved tools (allowed-tools): shell, http, file_write

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Confirm scope
  2. Passive subdomain enumeration with curl
  3. Liveness + tech fingerprinting with curl
  4. Content discovery with curl + a wordlist
  5. Summarize

What it can do on your machine

Read from SKILL.md and the folder at commit 0759d87. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • shell
    • http
    • file_write

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • crt.sh
    • otx.alienvault.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

External Recon Playbook loads about 1.2k tokens when it runs. Until then it costs about 59 tokens; SKILL.md has 406 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~59
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from PentesterFlow/agent at commit 0759d87, republished under its Apache-2.0 licence (© PentesterFlow). 406 words, ~1,183 tokens.

Download SKILL.mdSave it as .claude/skills/recon/SKILL.md (or your agent's skills folder).
name
recon
description
External recon playbook for a web target — subdomain enumeration, live-host probing, tech fingerprinting, and a first pass at content discovery. Use when the user gives you a root domain or apex and wants attack surface mapping.
allowed-tools
shell, http, file_write

Recon playbook

You have been asked to map the attack surface of a domain the user is authorized to test. Stay surgical — do not scan IP ranges or third-party assets.

Default to curl and the built-in http tool. Do not pull in specialized scanners (subfinder, httpx, ffuf, gobuster, etc.) unless the user explicitly asks for them.

Execution rule: substitute the real apex/host into commands before running them. Never write literal placeholders such as <APEX>, <HOST>, or <subdomains> to files. If the apex is unclear, ask once before running commands.

1. Confirm scope

Before running anything, restate the apex domain and ask the user to confirm it is in scope (only ask if scope was not already explicit in the conversation). Note any explicit out-of-scope subdomains or paths.

2. Passive subdomain enumeration with curl

Pull from public CT logs — no extra tooling required. Note: crt.sh is flaky and frequently answers with a 502/HTML page or an empty body instead of JSON. Piping that straight into jq is what throws jq: parse error: Invalid numeric literal. Validate the body is JSON before parsing, and retry with backoff:

# Robust crt.sh pull — quiet retries, parse only valid JSON.
APEX="example.com" # replace with the scoped apex before running
mkdir -p "recon/$APEX"
: > subs.txt
for attempt in 1 2 3; do
  resp=$(curl -fsS --max-time 30 -H 'Accept: application/json' \
    "https://crt.sh/?q=%25.$APEX&output=json" 2>/dev/null || true)
  if printf '%s' "$resp" | jq -e 'type == "array"' >/dev/null 2>&1; then
    printf '%s' "$resp" \
      | jq -r '.[].name_value' \
      | sed 's/^\*\.//' \
      | tr 'A-Z' 'a-z' | tr -d '\r' \
      | sort -u > subs.txt
    break
  fi
  sleep 3   # crt.sh is rate-limited / returns 502 under load
done
[ -s subs.txt ] || printf 'warning: crt.sh unavailable or returned non-JSON; try OTX or another source\n' >&2

name_value is newline-separated and may include wildcard (*.) entries; the sed/sort -u above normalizes and dedupes them. If /target is pinned, derive the real apex from that target before running.

For a second source, layer on AlienVault OTX (also guard the JSON):

APEX="example.com" # replace with the scoped apex before running
otx=$(curl -fsS --max-time 30 "https://otx.alienvault.com/api/v1/indicators/domain/$APEX/passive_dns" 2>/dev/null)
printf '%s' "$otx" | jq -e . >/dev/null 2>&1 \
  && printf '%s' "$otx" | jq -r '.passive_dns[].hostname' | sort -u >> subs.txt
sort -u -o subs.txt subs.txt

Save the deduped list with file_write to recon/$APEX/subs.txt.

Only reach for subfinder / amass / assetfinder if the user names them or the apex is large enough that crt.sh paging starts to drop results.

Show full SKILL.md (148 more words)Show less

3. Liveness + tech fingerprinting with curl

For each candidate, send a single GET and capture status, title, and key headers. Tight bash loop:

while read h; do
  curl -ksS -o /tmp/body -w "%{http_code}\t%{url_effective}\t%header{server}\t%header{x-powered-by}\n" \
    --max-time 8 "https://$h/" 2>/dev/null \
    | awk -F'\t' -v host="$h" '{title=""; getline title < "/tmp/body"; sub(/.*<title>/,"",title); sub(/<\/title>.*/,"",title); print $0"\t"title}'
done < subs.txt > httpx.txt

If you need more than that (favicon hashing, full tech fingerprinting on hundreds of hosts), say so and ask the user whether to install/run httpx.

4. Content discovery with curl + a wordlist

For 2-3 hosts that look custom (admin panels, staging, dashboards), do a focused wordlist sweep with curl:

HOST="app.example.com" # replace with an interesting live host before running
WORDLIST=/usr/share/seclists/Discovery/Web-Content/raft-small-words.txt
while read w; do
  code=$(curl -ksS -o /dev/null -w "%{http_code}" --max-time 5 "https://$HOST/$w")
  case "$code" in 200|204|301|302|401|403) echo "$code /$w";; esac
done < "$WORDLIST" | tee "ffuf-$HOST.txt"

Use -w "%{http_code} %{size_download}\n" if you also want to filter by body size. Pick a small wordlist first — escalate to medium only if the small one produces signal.

Only use ffuf or gobuster if the user explicitly asks for them.

5. Summarize

Write a recon/$APEX/summary.md with:

  • Counts: total subdomains, live hosts, by tech stack
  • Top 10 interesting hosts (with one-line reasons)
  • Candidate next steps (auth flows to inspect, admin endpoints, exposed configs, JS files worth diffing)

© PentesterFlow, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/recon of PentesterFlow/agent.

Open the folder on GitHubat commit 0759d87

Compare with similar skills

External Recon Playbook next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

External Recon Playbook compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
External Recon Playbook this skillPentesterFlow/agent1.4k—~1.2kAutomated safety check: PassApache-2.0
Metabigor OSINT Reconj3ssie/metabigor1.9k—~2.4kAutomated safety check: PassMIT
Wooyun Legacytanweai/wooyun-legacy1.8k—~1.9kAutomated safety check: PassCustom licence
Client Request Signature Reversalawarexone/Agentic-Bug-Hunter5.3k—~4.7kAutomated safety check: PassMIT
Web3 Bug Bounty AI Toolstradecatlabs/vibe-coding-cn17k2 repos~3.9kAutomated safety check: WarnMIT
Add Partial Reconsamugit83/redamon3k—~1.1kAutomated safety check: PassMIT

Similar skills

  • Metabigor OSINT Recon

    j3ssie/metabigor

    Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys.

    1.9k GitHub stars~2.4k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Wooyun Legacy

    tanweai/wooyun-legacy

    WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…

    1.8k GitHub stars~1.9k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Client Request Signature Reversal

    awarexone/Agentic-Bug-Hunter

    Recovers a client-side request signature or anti-bot token just far enough to replay blocked requests in bug bounty testing, starting from a captured packet.

    5.3k GitHub stars~4.7k tokensUpdated 3 days ago
    SecurityAuto-check passed
  • Web3 Bug Bounty AI Tools

    tradecatlabs/vibe-coding-cn

    A selection guide to AI-driven tools for Web3 bug bounty work, from autonomous web pentesters to smart contract bug finders, with notes on authorization.

    17k GitHub starsUsed in 2 repos~3.9k tokens
    SecurityAuto-check: warnings
  • Add Partial Recon

    samugit83/redamon

    Adding partial-recon support for a tool: running a single pipeline phase on demand from the workflow graph, reading its inputs from the existing Neo4j graph and merging results back.

    3k GitHub stars~1.1k tokensUpdated today
    SecurityAuto-check passed
  • Runs a bug-bounty engagement through a script that tracks the current pass, builds a board of rows from recon and prints the next required action each turn.

    329 GitHub starsUsed in 1 repo~1.8k tokens
    SecurityAuto-check passed

More from PentesterFlow/agent

  • Fingerprints which language or framework produced a serialized blob, then helps build a working gadget chain to test for insecure deserialization.

    1.4k GitHub stars~1.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Ssti

    PentesterFlow/agent

    Server-Side Template Injection — fingerprint the engine first (Jinja2 / Twig / Velocity / Freemarker / ERB / Smarty / Mako / Handlebars / Pug), then escalate the engine-specific primitive to RCE or…

    1.4k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Takeover

    PentesterFlow/agent

    Subdomain takeover playbook — sweep subdomains for dangling CNAMEs / NS records pointing at unclaimed third-party resources (GitHub Pages, S3, Heroku, Azure, Netlify, Shopify, ...), confirm with the…

    1.4k GitHub stars~3.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Webvuln

    PentesterFlow/agent

    Web vulnerability hunting playbook. An agent skill from PentesterFlow/agent.

    1.4k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about External Recon Playbook

What does External Recon Playbook do?

Maps the attack surface of a web domain you are authorized to test: confirms scope, lists subdomains from public sources, probes live hosts and fingerprints technology. The skill starts by restating the apex domain and asking you to confirm it is in scope, noting any out-of-scope subdomains or paths. It stays narrow, with no IP-range scans and no third-party assets, and it defaults to curl and the built-in http tool rather than specialized scanners such as subfinder, httpx, ffuf or gobuster unless you ask for them.

When should I use External Recon Playbook?

External Recon Playbook fits situations like: mapping the attack surface of a root domain you have permission to test; listing subdomains from certificate transparency logs without extra tools; checking which discovered hosts are live and what they run; preparing the recon stage of a bug bounty or pentest engagement.

How do I install External Recon Playbook in Claude Code?

Run `npx skills add PentesterFlow/agent --skill recon -a claude-code`. Or copy the skill folder (skills/recon in PentesterFlow/agent) into .claude/skills/recon in your project. Claude Code loads it when a task matches its description.

How do I install External Recon Playbook in Codex?

Run `npx skills add PentesterFlow/agent --skill recon -a codex`. Or copy the skill folder (skills/recon in PentesterFlow/agent) into .agents/skills/recon in your project. Codex loads it when a task matches its description.

Can I use External Recon Playbook in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PentesterFlow/agent --skill recon -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/recon, .gemini/skills/recon, .github/skills/recon and .opencode/skills/recon in your project.

What does External Recon Playbook need to run?

Going by SKILL.md and its folder, External Recon Playbook needs the command-line tools its instructions call (curl and jq). Our summary lists: Authorization to test the target domain; curl and jq, with network access to public CT log and passive DNS sources. Its frontmatter pre-approves these tools: shell, http, file_write.

Does External Recon Playbook access the network?

SKILL.md names 2 domains. In commands or code: crt.sh and otx.alienvault.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is External Recon Playbook safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does External Recon Playbook use?

External Recon Playbook is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does External Recon Playbook use?

About 1.2k tokens (SKILL.md is roughly 4.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to External Recon Playbook?

Skills that share tags, products or a category with External Recon Playbook: Metabigor OSINT Recon (j3ssie/metabigor, 1.9k stars), Wooyun Legacy (tanweai/wooyun-legacy, 1.8k stars), Client Request Signature Reversal (awarexone/Agentic-Bug-Hunter, 5.3k stars) and Web3 Bug Bounty AI Tools (tradecatlabs/vibe-coding-cn, 17k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains External Recon Playbook?

PentesterFlow (a GitHub user) maintains it in PentesterFlow/agent, which has 1,391 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on August 31, 2026.

Source: PentesterFlow/agent on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.