Metabigor OSINT Recon
j3ssie/metabigor
Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys.
Adding a new tool to the recon pipeline: the enrichment-module contract and its isolated wrapper (the actual fan-out and test call path), graph completeness, and the preset catalog that silently…
$ npx skills add samugit83/redamon --skill recon-tool-integration -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install samugit83/redamon recon-tool-integration --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/samugit83/redamon.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/recon-tool-integration .claude/skills/recon-tool-integration && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "recon-tool-integration" agent skill from https://github.com/samugit83/redamon/tree/master/skills/recon-tool-integration into .claude/skills/recon-tool-integration/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "recon-tool-integration", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/samugit83/redamon/tree/master/skills/recon-tool-integrationType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add samugit83/redamon --skill recon-tool-integration -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install samugit83/redamon recon-tool-integration --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/samugit83/redamon.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/recon-tool-integration .agents/skills/recon-tool-integration && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "recon-tool-integration" agent skill from https://github.com/samugit83/redamon/tree/master/skills/recon-tool-integration into .agents/skills/recon-tool-integration/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "recon-tool-integration", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add samugit83/redamon --skill recon-tool-integration -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install samugit83/redamon recon-tool-integration --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/samugit83/redamon.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/recon-tool-integration .cursor/skills/recon-tool-integration && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "recon-tool-integration" agent skill from https://github.com/samugit83/redamon/tree/master/skills/recon-tool-integration into .cursor/skills/recon-tool-integration/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "recon-tool-integration", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/samugit83/redamon.git --path skills/recon-tool-integration--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add samugit83/redamon --skill recon-tool-integration -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install samugit83/redamon recon-tool-integration --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/samugit83/redamon.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/recon-tool-integration .gemini/skills/recon-tool-integration && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "recon-tool-integration" agent skill from https://github.com/samugit83/redamon/tree/master/skills/recon-tool-integration into .gemini/skills/recon-tool-integration/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "recon-tool-integration", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install samugit83/redamon recon-tool-integrationInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add samugit83/redamon --skill recon-tool-integration -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/samugit83/redamon.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/recon-tool-integration .github/skills/recon-tool-integration && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "recon-tool-integration" agent skill from https://github.com/samugit83/redamon/tree/master/skills/recon-tool-integration into .github/skills/recon-tool-integration/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "recon-tool-integration", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add samugit83/redamon --skill recon-tool-integration -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install samugit83/redamon recon-tool-integration --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/samugit83/redamon.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/recon-tool-integration .opencode/skills/recon-tool-integration && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "recon-tool-integration" agent skill from https://github.com/samugit83/redamon/tree/master/skills/recon-tool-integration into .opencode/skills/recon-tool-integration/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "recon-tool-integration", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
recon-tool-integrationAdding a new tool to the recon pipeline: the enrichment-module contract and its isolated wrapper (the actual fan-out and test call path), graph completeness, and the preset catalog that silently…
Recon Tool Integration is an agent skill from samugit83/redamon. Adding a new tool to the recon pipeline: the enrichment-module contract and its isolated wrapper (the actual fan-out and test call path), graph completeness, and the preset catalog that silently strips unknown settings. Miss the isolated wrapper and the tool never runs in parallel; miss the catalog and AI presets drop its config. Trigger: adding a tool to the recon pipeline; a new recon/.py or recon/mainreconmodules/.py enrichment module; editing the execution groups in recon/main.py or the IMAGES array in…
Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Penetration testing and Bug bounty. The repository describes itself as: Open-source, self-hosted AI penetration testing framework: maps your attack surface into a graph, autonomously exploits it from a Kali sandbox with human approval gates, and… The licence is MIT.
Read from SKILL.md and the folder at commit d90c940. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
dockerpython3From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use docker, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Recon Tool Integration loads about 1.9k tokens when it runs. Until then it costs about 140 tokens; SKILL.md has 693 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from samugit83/redamon at commit d90c940, republished under its MIT licence (© samugit83). 693 words, ~1,885 tokens.
.claude/skills/recon-tool-integration/SKILL.md (or your agent's skills folder).For adding AI decision-making to an existing tool, use recon-ai-enrichment.
For the graph write, use graph-db-writes. For the settings, use
project-settings-cascade. This skill is the module + pipeline wiring.
_isolated wrapper.
run_<tool>_enrichment_isolated() is the actual call path for the GROUP 3b
parallel fan-out AND for every unit test; the plain run_<tool>_enrichment()
alone is never fan-out-safe. Reference:
recon/main_recon_modules/censys_enrich.py:369.combined_result["<tool>"] and the wrapper returns snapshot.get("<tool>", {})
with the same identifier used everywhere else in the pipeline
(censys_enrich.py:365).graph-db-writes.RECON_PARAMETER_CATALOG in
webapp/src/app/api/presets/generate/route.ts.
Miss the Zod schema and AI-generated presets silently strip the setting;
miss the catalog and the preset LLM never knows the tool exists.print() log [symbol][ToolName] ([*] progress,
[+] success, [-] skipped, [!] error). Recon stdout is tailed into the SSE
recon drawer; a bare print() is invisibly formatted._isolated wrapper and in
the correct execution group in recon/main.py; never
parallelize across a dependency boundary (a tool needing live URLs cannot run
before GROUP 4).Breaker (guarded_call, or a provider:endpoint
breaker with record(classify_http(...))); its keys go through a KeyPool, not
a raw main-key read. A loop over scan hosts (HTTP or a Docker tool) gates each
host with host_health.allow(url) / scope.skip_if_down(url) and records the
outcome with host_alive / host_failed — any HTTP response is life, only a
connection failure counts. Never log a key or a response body: breaker messages
carry the provider, endpoint and a refused key's 1-based rotation position only.scope = circuit_breaker.scope((), label="Tool", unit="host(s)") at the tool's
start and call scope.finish("<phase>", sources=[...], host_source="<graph source>", payload=result) at its end — so the end-of-run prune KEEPS a paused
source's or a skipped host's prior findings instead of deleting them as "gone",
and the run shows partial — N sources skipped. host_source must equal the
source value the tool writes to the graph. A tool whose findings carry no host
field passes host_field=False (the skip is reported at the source level).Prisma.ProjectScalarFieldEnum fails until every column
has an entry. Draft it with
python3 tooling/scripts/extract_recon_registry.py, EDIT IT, then
python3 recon_settings/build.py.values: list and an out-of-set value is REFUSED at the write, because
accepting one and replacing it at scan start made get_recon_settings echo an
image the scan would never run.mcp: create_only, set once by create_project) and the engagement RECORD
(mcp: never, deny_reason: engagement-record - the client, the contacts,
the dates, the document). The engagement's LIMITS are ordinary mcp: settable
fields in the engagement_limits group: they are reachable from the form and
from MCP alike, and what makes them safe is that each is enforced at scan
start whatever the setting says. See
README.MCP.SERVER.md.parity.test.ts, and so does a
form input with no classification. Neither door may reach something the
other cannot. form_section is joined from the tool's own entry, so a field
lands beside its tool automatically.rps field with traffic: active and no roe_capped: true fails the
build. That gap is how three rate limits shipped reachable over MCP and
outside the ceiling.def run_censys_enrichment(combined_result: dict, settings: dict) -> dict:
... # mutate in place
combined_result["censys"] = censys_data # top-level key == tool id, everywhere
return combined_result
def run_censys_enrichment_isolated(combined_result: dict, settings: dict) -> dict:
"""Thread-safe: does not mutate combined_result. The fan-out + test call path."""
import copy
snapshot = copy.deepcopy(combined_result)
run_censys_enrichment(snapshot, settings)
return snapshot.get("censys", {}) # returns only this tool's payloadFrom recon/main_recon_modules/censys_enrich.py.
docker compose build recon # if you added a Docker-based tool (recon/entrypoint.sh IMAGES)
docker compose exec webapp npx prisma db push # for new settings (NEVER prisma migrate)
./redamon.sh test unit # recon + root-recon sectionsgraph-db-writes, project-settings-cascade, recon-ai-enrichment© samugit83, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/recon-tool-integration of samugit83/redamon.
Open the folder on GitHubat commit d90c940
Recon Tool Integration next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Recon Tool Integration this skillsamugit83/redamon | 3k | — | ~1.9k | Automated safety check: Pass | MIT | |
| Metabigor OSINT Reconj3ssie/metabigor | 1.9k | — | ~2.4k | Automated safety check: Pass | MIT | |
| Wooyun Legacytanweai/wooyun-legacy | 1.8k | — | ~1.9k | Automated safety check: Pass | Custom licence | |
| Client Request Signature Reversalawarexone/Agentic-Bug-Hunter | 5.3k | — | ~4.7k | Automated safety check: Pass | MIT | |
| Web3 Bug Bounty AI Toolstradecatlabs/vibe-coding-cn | 17k | 2 repos | ~3.9k | Automated safety check: Warn | MIT | |
| Bug Bounty Campaign DriverEncod3d-Sec/TORCH | 329 | 1 repos | ~1.8k | Automated safety check: Pass | MIT |
j3ssie/metabigor
Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys.
tanweai/wooyun-legacy
WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…
awarexone/Agentic-Bug-Hunter
Recovers a client-side request signature or anti-bot token just far enough to replay blocked requests in bug bounty testing, starting from a captured packet.
tradecatlabs/vibe-coding-cn
A selection guide to AI-driven tools for Web3 bug bounty work, from autonomous web pentesters to smart contract bug finders, with notes on authorization.
Encod3d-Sec/TORCH
Runs a bug-bounty engagement through a script that tracks the current pass, builds a board of rows from recon and prints the next required action each turn.
Encod3d-Sec/TORCH
Adaptive web fuzzing for pentests, bug bounty and CTF work: picks the smallest suitable SecLists wordlist per target surface and calibrates filters against soft-404 responses.
samugit83/redamon
Adding a Community Agent Skill: a Markdown attack-workflow file that users import from the catalog, which then competes in the Intent Router and is injected into the agent's system prompt.
samugit83/redamon
Adding partial-recon support for a tool: running a single pipeline phase on demand from the workflow graph, reading its inputs from the existing Neo4j graph and merging results back.
samugit83/redamon
Wiring a new tool the AI agent can call (not the recon pipeline): the tool registry, the phase map, the hardcoded dispatch chokepoint, and the duplicated execution paths that make a tool work in…
samugit83/redamon
Adding a built-in Agent Skill (an attack technique like ssrf, xxe, rce) that ships hardcoded in RedAmon: classified by the Intent Router, injected into the agent prompt, toggled per project, badged…
samugit83/redamon
Writing to the Neo4j attack-surface graph in RedAmon: the tenant-isolation MERGE key every entity node must carry, where graph methods live (mixins, not the client), and the schema places that must…
samugit83/redamon
Adding an LLM provider to RedAmon: the credential boundary (keys must never reach scan containers), prefix-routed model ids, and the provider registry.
Categories
Adding a new tool to the recon pipeline: the enrichment-module contract and its isolated wrapper (the actual fan-out and test call path), graph completeness, and the preset catalog that silently…. Recon Tool Integration is an agent skill from samugit83/redamon. Adding a new tool to the recon pipeline: the enrichment-module contract and its isolated wrapper (the actual fan-out and test call path), graph completeness, and the preset catalog that silently strips unknown settings.
Recon Tool Integration fits situations like: tasks that involve Penetration testing; tasks that involve Bug bounty.
Run `npx skills add samugit83/redamon --skill recon-tool-integration -a claude-code`. Or copy the skill folder (skills/recon-tool-integration in samugit83/redamon) into .claude/skills/recon-tool-integration in your project. Claude Code loads it when a task matches its description.
Run `npx skills add samugit83/redamon --skill recon-tool-integration -a codex`. Or copy the skill folder (skills/recon-tool-integration in samugit83/redamon) into .agents/skills/recon-tool-integration in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add samugit83/redamon --skill recon-tool-integration -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/recon-tool-integration, .gemini/skills/recon-tool-integration, .github/skills/recon-tool-integration and .opencode/skills/recon-tool-integration in your project.
Going by SKILL.md and its folder, Recon Tool Integration needs the command-line tools its instructions call (docker and python3). Our summary lists: Python 3; Node.js; Docker.
SKILL.md contains no URLs. Its commands use docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Recon Tool Integration is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.9k tokens (SKILL.md is roughly 7.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Recon Tool Integration: Metabigor OSINT Recon (j3ssie/metabigor, 1.9k stars), Wooyun Legacy (tanweai/wooyun-legacy, 1.8k stars), Client Request Signature Reversal (awarexone/Agentic-Bug-Hunter, 5.3k stars) and Web3 Bug Bounty AI Tools (tradecatlabs/vibe-coding-cn, 17k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
samugit83 (a GitHub user) maintains it in samugit83/redamon, which has 2,961 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on October 7, 2026.
Source: samugit83/redamon on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.