Metabigor OSINT Recon
j3ssie/metabigor
Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys.
Wiring an LLM into a recon tool's decisions ("let AI pick {feature} for {tool}"): the never-raise contract, the per-target cache, the full+partial coverage, and the two UI toggles bound to one field.
$ npx skills add samugit83/redamon --skill recon-ai-enrichment -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install samugit83/redamon recon-ai-enrichment --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/samugit83/redamon.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/recon-ai-enrichment .claude/skills/recon-ai-enrichment && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "recon-ai-enrichment" agent skill from https://github.com/samugit83/redamon/tree/master/skills/recon-ai-enrichment into .claude/skills/recon-ai-enrichment/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "recon-ai-enrichment", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/samugit83/redamon/tree/master/skills/recon-ai-enrichmentType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add samugit83/redamon --skill recon-ai-enrichment -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install samugit83/redamon recon-ai-enrichment --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/samugit83/redamon.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/recon-ai-enrichment .agents/skills/recon-ai-enrichment && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "recon-ai-enrichment" agent skill from https://github.com/samugit83/redamon/tree/master/skills/recon-ai-enrichment into .agents/skills/recon-ai-enrichment/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "recon-ai-enrichment", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add samugit83/redamon --skill recon-ai-enrichment -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install samugit83/redamon recon-ai-enrichment --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/samugit83/redamon.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/recon-ai-enrichment .cursor/skills/recon-ai-enrichment && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "recon-ai-enrichment" agent skill from https://github.com/samugit83/redamon/tree/master/skills/recon-ai-enrichment into .cursor/skills/recon-ai-enrichment/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "recon-ai-enrichment", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/samugit83/redamon.git --path skills/recon-ai-enrichment--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add samugit83/redamon --skill recon-ai-enrichment -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install samugit83/redamon recon-ai-enrichment --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/samugit83/redamon.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/recon-ai-enrichment .gemini/skills/recon-ai-enrichment && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "recon-ai-enrichment" agent skill from https://github.com/samugit83/redamon/tree/master/skills/recon-ai-enrichment into .gemini/skills/recon-ai-enrichment/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "recon-ai-enrichment", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install samugit83/redamon recon-ai-enrichmentInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add samugit83/redamon --skill recon-ai-enrichment -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/samugit83/redamon.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/recon-ai-enrichment .github/skills/recon-ai-enrichment && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "recon-ai-enrichment" agent skill from https://github.com/samugit83/redamon/tree/master/skills/recon-ai-enrichment into .github/skills/recon-ai-enrichment/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "recon-ai-enrichment", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add samugit83/redamon --skill recon-ai-enrichment -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install samugit83/redamon recon-ai-enrichment --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/samugit83/redamon.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/recon-ai-enrichment .opencode/skills/recon-ai-enrichment && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "recon-ai-enrichment" agent skill from https://github.com/samugit83/redamon/tree/master/skills/recon-ai-enrichment into .opencode/skills/recon-ai-enrichment/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "recon-ai-enrichment", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
recon-ai-enrichmentWiring an LLM into a recon tool's decisions ("let AI pick {feature} for {tool}"): the never-raise contract, the per-target cache, the full+partial coverage, and the two UI toggles bound to one field.
Recon AI Enrichment is an agent skill from samugit83/redamon. Wiring an LLM into a recon tool's decisions ("let AI pick {feature} for {tool}"): the never-raise contract, the per-target cache, the full+partial coverage, and the two UI toggles bound to one field. A raising AI helper or an empty fallback silently breaks or disables a live scan. Trigger: adding or editing a recon AI hook; a new recon/helpers/aiplanner/{tool}{feature}.py; a /llm/{tool}-{feature} endpoint in agentic/api.py; a data.{tool}Ai{feature} toggle; editing applyaipipelineoverrides in…
Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Penetration testing and Bug bounty. The repository describes itself as: Open-source, self-hosted AI penetration testing framework: maps your attack surface into a graph, autonomously exploits it from a Kali sandbox with human approval gates, and… The licence is MIT.
Read from SKILL.md and the folder at commit 5dd993c. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
dockerFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use docker, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Recon AI Enrichment loads about 2.2k tokens when it runs. Until then it costs about 176 tokens; SKILL.md has 924 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from samugit83/redamon at commit 5dd993c, republished under its MIT licence (© samugit83). 924 words, ~2,246 tokens.
.claude/skills/recon-ai-enrichment/SKILL.md (or your agent's skills folder).For adding a whole new recon tool, use recon-tool-integration. For the setting
that toggles it, use project-settings-cascade.
current_tags on any failure").[]/"".agent_llm breaker AFTER the cache check, and honour it by
returning the existing fallback. The agent's /llm/* endpoints share one
breaker: gate = agent_llm_gate() (from
recon/helpers/ai_planner/init.py);
when not gate.allowed, print "... Agent LLM paused (breaker open) - using the
fallback." and return the user's current value WITHOUT a POST. After the POST
call gate.record(resp=resp); in the except branch call gate.record(exc=e).
The cache is checked first so a cached answer is still served while the breaker
is open. This is the same never-raise/never-empty fallback as above — the
breaker just skips the call that would fail anyway when the agent is down.engine: str = "llm" and uses
its OWN breaker. engine == "jev" posts to /jev/<hook> (same request body,
same response shape as /llm/<hook>, so the existing validator is reused),
takes agent_jev_gate() and logs [*][<Tool>-Jev]. Never record a Jev outcome
on agent_llm: that breaker marks 401/402/403 FATAL for the whole run, so a Jev
auth or credit failure would silence every LLM hook. The Jev gate reads the
agent's 503 error_type (no token, auth, no credit, forbidden are FATAL; rate
limited carries retry_after; the rest are transient). A Jev failure uses the
hook's static fallback: never re-route to the LLM, never return empty.aiInPipeline forces each per-hook AI flag; the {tool}AiUseJev engine
fields stay OUT of apply_ai_pipeline_overrides, are in KEPT_WHEN_ABSENT
(webapp/src/lib/project-preset-utils.ts) so a preset apply does not reset
them, and a switch-ON is refused server-side unless the project OWNER has a Jev
token (validateJevEngineChange, every write path, fail closed). Give a hook a
Jev engine only when a wrong answer cannot drop a finding: the Nuclei
false-positive filter deletes findings from target-controlled bytes and has no
Jev engine.{tool}Jev{Feature}, no LLM twin) has TWO levels and
starts in shadow. Nothing upstream folds its flag into aiInPipeline, so
EVERY call site, full and partial, tests AI_IN_PIPELINE and <FLAG> itself;
never add it to the master fan-out in TargetSection.tsx. Build it on
recon/helpers/ai_planner/jev_shadow.py (jev_post takes the agent_jev
breaker; ShadowRecorder caps the per-decision lines at 50, prints one
summary, and keeps the records in the recon JSON under jev_shadow.<hook>).
ROLLOUT = SHADOW acts on the deterministic path; ROLLOUT = ACT acts on
Jev's answer with the deterministic result as the fallback, and flipping a
hook is a separate change. In AI_HOOKS it is kind: 'enable', so a false flag
reports off, not llm._ask_items, which sends each request only its own items; _ask re-sends
one state per chunk and a scan's items would exceed the request limit.run_vuln_scan is called by both main_recon_modules/ and
partial_recon_modules/); hook it once and both paths inherit. grep the
function name to confirm before you edit. The feature must work in the full
pipeline AND partial recon.aiInPipeline cascade (apply_ai_pipeline_overrides,
recon/project_settings.py:1968) is the
single source of truth for per-tool AI flags. Presets must not hard-code them;
update the Zod schema instead.Project column {tool}Ai{Feature}
in recon_settings/registry.yaml, beside
ffufAiExtensions, nucleiAiTags, nucleiAiResponseFilter and
wafAiClassifier. A test walking Prisma.ProjectScalarFieldEnum fails until
every column has one. An AI hook is an ordinary boolean toggle: mcp: settable, traffic: none (the hook itself sends no traffic; the tool it
advises does), and a meaning that says which decision it moves from the
operator to the model.data.{tool}Ai{Feature}: the master AI-in-Pipeline panel
(TargetSection.tsx:695)
and the tool's own section (e.g.
NucleiSection.tsx).
Read AND write the same field; no copy-on-flip (they stay in sync because
they share the field).| Piece | File | Note |
|---|---|---|
| Helper | recon/helpers/ai_planner/{tool}_{feature}.py | POSTs to the agent; never raises; logs [*][{Tool}-AI] / [!][{Tool}-AI] to stdout |
| Agent endpoint | agentic/api.py (e.g. /llm/nuclei-tags at :641, /llm/ffuf-extensions at :543) | Pydantic model; returns 422 (bad body) / 503 (no key), never 500 |
| Setting | recon/project_settings.py DEFAULT_SETTINGS + fetch_project_settings + both branches of apply_ai_pipeline_overrides | see project-settings-cascade |
| Zod | webapp/src/lib/recon-preset-schema.ts | so AI-generated presets see the field |
| UI | TargetSection.tsx + the tool's section | two toggles, one field |
docker compose build agent && docker compose up -d agent # the /llm endpoint lives in agentic/ (baked)
# recon/*.py is volume-mounted at spawn - no rebuild
# verify: a minimal POST returns 422/503, never 500; and a live scan logs
# [*][{Tool}-AI] in BOTH a full run and a partial recon run; stop the agent -> scan still completes.recon-tool-integration, project-settings-cascade© samugit83, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/recon-ai-enrichment of samugit83/redamon.
Open the folder on GitHubat commit 5dd993c
Recon AI Enrichment next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Recon AI Enrichment this skillsamugit83/redamon | 3k | — | ~2.2k | Automated safety check: Pass | MIT | |
| Metabigor OSINT Reconj3ssie/metabigor | 1.9k | — | ~2.4k | Automated safety check: Pass | MIT | |
| Wooyun Legacytanweai/wooyun-legacy | 1.8k | — | ~1.9k | Automated safety check: Pass | Custom licence | |
| Client Request Signature Reversalawarexone/Agentic-Bug-Hunter | 5.3k | — | ~4.7k | Automated safety check: Pass | MIT | |
| Web3 Bug Bounty AI Toolstradecatlabs/vibe-coding-cn | 17k | 2 repos | ~3.9k | Automated safety check: Warn | MIT | |
| Bug Bounty Campaign DriverEncod3d-Sec/TORCH | 329 | — | ~1.8k | Automated safety check: Pass | MIT |
j3ssie/metabigor
Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys.
tanweai/wooyun-legacy
WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…
awarexone/Agentic-Bug-Hunter
Recovers a client-side request signature or anti-bot token just far enough to replay blocked requests in bug bounty testing, starting from a captured packet.
tradecatlabs/vibe-coding-cn
A selection guide to AI-driven tools for Web3 bug bounty work, from autonomous web pentesters to smart contract bug finders, with notes on authorization.
Encod3d-Sec/TORCH
Runs a bug-bounty engagement through a script that tracks the current pass, builds a board of rows from recon and prints the next required action each turn.
PentesterFlow/agent
Maps the attack surface of a web domain you are authorized to test: confirms scope, lists subdomains from public sources, probes live hosts and fingerprints technology.
samugit83/redamon
Adding a Community Agent Skill: a Markdown attack-workflow file that users import from the catalog, which then competes in the Intent Router and is injected into the agent's system prompt.
samugit83/redamon
Adding partial-recon support for a tool: running a single pipeline phase on demand from the workflow graph, reading its inputs from the existing Neo4j graph and merging results back.
samugit83/redamon
Wiring a new tool the AI agent can call (not the recon pipeline): the tool registry, the phase map, the hardcoded dispatch chokepoint, and the duplicated execution paths that make a tool work in…
samugit83/redamon
Adding a built-in Agent Skill (an attack technique like ssrf, xxe, rce) that ships hardcoded in RedAmon: classified by the Intent Router, injected into the agent prompt, toggled per project, badged…
samugit83/redamon
Writing to the Neo4j attack-surface graph in RedAmon: the tenant-isolation MERGE key every entity node must carry, where graph methods live (mixins, not the client), and the schema places that must…
samugit83/redamon
Adding an LLM provider to RedAmon: the credential boundary (keys must never reach scan containers), prefix-routed model ids, and the provider registry.
Categories
Wiring an LLM into a recon tool's decisions ("let AI pick {feature} for {tool}"): the never-raise contract, the per-target cache, the full+partial coverage, and the two UI toggles bound to one field. Recon AI Enrichment is an agent skill from samugit83/redamon. Wiring an LLM into a recon tool's decisions ("let AI pick {feature} for {tool}"): the never-raise contract, the per-target cache, the full+partial coverage, and the two UI toggles bound to one field.
Recon AI Enrichment fits situations like: tasks that involve Penetration testing; tasks that involve Bug bounty.
Run `npx skills add samugit83/redamon --skill recon-ai-enrichment -a claude-code`. Or copy the skill folder (skills/recon-ai-enrichment in samugit83/redamon) into .claude/skills/recon-ai-enrichment in your project. Claude Code loads it when a task matches its description.
Run `npx skills add samugit83/redamon --skill recon-ai-enrichment -a codex`. Or copy the skill folder (skills/recon-ai-enrichment in samugit83/redamon) into .agents/skills/recon-ai-enrichment in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add samugit83/redamon --skill recon-ai-enrichment -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/recon-ai-enrichment, .gemini/skills/recon-ai-enrichment, .github/skills/recon-ai-enrichment and .opencode/skills/recon-ai-enrichment in your project.
Going by SKILL.md and its folder, Recon AI Enrichment needs the command-line tools its instructions call (docker). Our summary lists: Docker.
SKILL.md contains no URLs. Its commands use docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Recon AI Enrichment is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.2k tokens (SKILL.md is roughly 9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Recon AI Enrichment: Metabigor OSINT Recon (j3ssie/metabigor, 1.9k stars), Wooyun Legacy (tanweai/wooyun-legacy, 1.8k stars), Client Request Signature Reversal (awarexone/Agentic-Bug-Hunter, 5.3k stars) and Web3 Bug Bounty AI Tools (tradecatlabs/vibe-coding-cn, 17k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
samugit83 (a GitHub user) maintains it in samugit83/redamon, which has 2,982 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on October 8, 2026.
Source: samugit83/redamon on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.