Agent skill

Performing Reconnaissance

by trilwu in trilwu/secskills

Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access.

MITAuto-check: notesSecurity

Install Performing Reconnaissance

skills CLI
$ npx skills add trilwu/secskills --skill performing-reconnaissance -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trilwu/secskills performing-reconnaissance --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/secskills-offense/skills/performing-reconnaissance .claude/skills/performing-reconnaissance && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
performing-reconnaissance
GitHub stars
157
Token cost
~3.1k tokens
SKILL.md length
585 words
Files
2 (incl. references)
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access.

  • Works in 7 steps: Passive Reconnaissance (OSINT) → Active Reconnaissance → Web Application Reconnaissance → …
  • Gathering intelligence
  • SKILL.md covers When to Use, When NOT to Use, Core Methodologies and Essential Tools, plus 3 more sections
  • Calls python3, curl and jq; reaches crt.sh

What it does

Performing Reconnaissance is an agent skill from trilwu/secskills. Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access. Use when gathering intelligence or mapping attack surface.

Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/cloud-vuln-credential-tooling.md`).

It sits in Security, covering OSINT and Threat modeling. The repository describes itself as: Transform Claude Code into your personal security engineer. The licence is MIT.

When your agent uses it

  • Gathering intelligence
  • Mapping attack surface

Example prompts

  • “/performing-reconnaissance”

Requirements

  • Python 3

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Passive Reconnaissance (OSINT)
  2. Active Reconnaissance
  3. Web Application Reconnaissance
  4. Email/Phishing Reconnaissance
  5. Network Mapping
  6. Attack Surface Mapping
  7. Reporting and Documentation

What it can do on your machine

Read from SKILL.md and the folder at commit ca53957. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3
    • curl
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • crt.sh

    Also links to:

    • attack.mitre.org
    • github.com
    • owasp.org
    • book.hacktricks.xyz

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Performing Reconnaissance loads about 3.1k tokens when it runs, and up to ~3.8k if it reads all its reference files. Until then it costs about 55 tokens; SKILL.md has 585 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~55
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:190
    sudo nmap -sU --top-ports 1000 target.com
  • NoteRuns commands with sudoSKILL.md:197
    sudo masscan -p1-65535 10.10.10.10 --rate=1000
  • NoteRuns commands with sudoSKILL.md:214
    sudo nmap -O target.com
  • NoteMentions a .env fileSKILL.md:255
    /.env
  • NoteRuns commands with sudoSKILL.md:341
    sudo arp-scan -l
  • NoteRuns commands with sudoSKILL.md:342
    sudo netdiscover -r 10.10.10.0/24

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from trilwu/secskills at commit ca53957, republished under its MIT licence (© trilwu). 585 words, ~3,104 tokens.

Download SKILL.mdSave it as .claude/skills/performing-reconnaissance/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
performing-reconnaissance
description
Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access. Use when gathering intelligence or mapping attack surface.
verified
2026-07-27

Initial Access and Reconnaissance Skill

You are an offensive security expert specializing in reconnaissance, OSINT, and initial access techniques. Use this skill when the user requests help with:

  • External reconnaissance and information gathering
  • Subdomain enumeration
  • Port scanning strategies
  • OSINT techniques
  • Public exposure detection
  • Network mapping
  • Service fingerprinting
  • Vulnerability scanning

When to Use

Activate this skill when the user asks to:

  • Perform reconnaissance on a target
  • Enumerate subdomains
  • Discover attack surface
  • Find public exposures
  • Gather OSINT information
  • Map network infrastructure
  • Identify technologies in use
  • Help with initial access techniques

Scope and authorization. Passive collection against public sources is generally lawful; the moment you send packets to a host you are acting under whatever authorization you hold, and unauthorized scanning is a criminal offense in most jurisdictions (CFAA in the US, Computer Misuse Act in the UK). Two failure modes specific to recon:

  • Inherited infrastructure. Subdomain and ASN enumeration walks into third-party estate constantly — the CDN, the SaaS tenant, the shared host, the acquired subsidiary nobody listed. Resolve ownership before you probe; "it was in the DNS tree" is not authorization.
  • OSINT on people. Employee enumeration, credential-dump correlation, and social-profile harvesting are personal-data processing under GDPR and similar regimes. Confirm the engagement covers it, and keep what you collect inside the engagement.

Get the target list, the explicitly excluded ranges, and the active-testing window in writing before the first active probe.

When NOT to Use

  • You already have network access — use enumerating-network-services
  • Code-level review of a known target — use auditing-code-for-vulnerabilities
  • Pretext development for a phishing campaign — use performing-social-engineering
  • Investigating an adversary rather than a target — use hunting-threats

If enumeration surfaces credentials or a service in an implausibly convenient place, stop and consult recognizing-deception before using them — canary tokens fire on first use. Record where every artifact came from as you go; maintaining-engagement-state explains why unattributable findings are unusable later.

Core Methodologies

1. Passive Reconnaissance (OSINT)

Domain Information:

bash
# WHOIS lookup
whois domain.com

# DNS records
dig domain.com ANY
dig domain.com MX
dig domain.com TXT
dig domain.com NS

# Historical DNS data
# Use: SecurityTrails, DNSdumpster, Shodan

Subdomain Enumeration (Passive):

bash
# Certificate transparency logs
curl -s "https://crt.sh/?q=%25.domain.com&output=json" | jq -r '.[].name_value' | sort -u

# Sublist3r
python3 sublist3r.py -d domain.com

# Amass (passive)
amass enum -passive -d domain.com

# assetfinder
assetfinder --subs-only domain.com

# subfinder
subfinder -d domain.com -silent

Email Harvesting:

bash
# theHarvester
theHarvester -d domain.com -b all

# hunter.io (web interface or API)
# phonebook.cz
# clearbit connect

Search Engine Recon:

bash
# Google Dorks
site:domain.com filetype:pdf
site:domain.com inurl:admin
site:domain.com intitle:"index of"
site:domain.com ext:sql | ext:txt | ext:log

# GitHub Dorks
"domain.com" password
"domain.com" api_key
"domain.com" secret
org:company password
org:company api

Shodan/Censys:

bash
# Shodan CLI
shodan search "hostname:domain.com"
shodan search "org:Company Name"
shodan search "ssl:domain.com"

# Censys
# Use web interface or API
# Search for: domain.com or company infrastructure

Social Media OSINT:

bash
# LinkedIn enumeration
# Company employees, job titles, technologies used

# Twitter
# Company accounts, employee accounts, technology mentions

# Tools:
# - linkedin2username (generate username lists)
# - sherlock (find usernames across platforms)
2. Active Reconnaissance

Subdomain Enumeration (Active):

bash
# gobuster
gobuster dns -d domain.com -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-20000.txt

# ffuf
ffuf -u http://FUZZ.domain.com -w subdomains.txt -mc 200,301,302

# dnsrecon
dnsrecon -d domain.com -t brt -D subdomains.txt

# amass (active)
amass enum -active -d domain.com -brute

DNS Zone Transfer:

bash
# dig
dig axfr @ns1.domain.com domain.com

# host
host -l domain.com ns1.domain.com

# fierce
fierce --domain domain.com

Port Scanning:

bash
# Nmap - quick scan
nmap -sC -sV -oA nmap_scan target.com

# Nmap - full port scan
nmap -p- -T4 -oA nmap_full target.com
nmap -p- -sV -sC -A target.com -oA nmap_detailed

# Nmap - UDP scan
sudo nmap -sU --top-ports 1000 target.com

# Nmap - scan entire network
nmap -sn 10.10.10.0/24  # Ping sweep
nmap -p- 10.10.10.0/24  # Port scan subnet

# masscan (very fast)
sudo masscan -p1-65535 10.10.10.10 --rate=1000

# rustscan (fast with nmap integration)
rustscan -a target.com -- -sC -sV

Service Detection:

bash
# Banner grabbing
nc -nv target.com 80
curl -I https://target.com
telnet target.com 80

# Nmap service detection
nmap -sV --version-intensity 9 target.com

# OS detection
sudo nmap -O target.com
3. Web Application Reconnaissance

Technology Identification:

bash
# WhatWeb
whatweb https://target.com

# Wappalyzer (browser extension)
# BuiltWith (web service)

# Check headers
curl -I https://target.com

# Check response
curl -s https://target.com | grep -i "powered by\|framework\|generator"

Directory/File Enumeration:

bash
# gobuster
gobuster dir -u https://target.com -w /usr/share/wordlists/dirb/common.txt
gobuster dir -u https://target.com -w /usr/share/seclists/Discovery/Web-Content/raft-large-words.txt -x php,txt,html

# feroxbuster (recursive)
feroxbuster -u https://target.com -w wordlist.txt -x php,txt,html,js

# ffuf
ffuf -u https://target.com/FUZZ -w wordlist.txt -mc 200,301,302,403
ffuf -u https://target.com/FUZZ -w wordlist.txt -fc 404  # Filter out 404s

# dirsearch
dirsearch -u https://target.com -e php,html,js

# Common paths to check manually
/robots.txt
/sitemap.xml
/.git/
/.svn/
/.env
/backup/
/admin/
/phpmyadmin/

Virtual Host Discovery:

bash
# gobuster
gobuster vhost -u http://target.com -w vhosts.txt

# ffuf
ffuf -u http://target.com -H "Host: FUZZ.target.com" -w vhosts.txt -fc 404

Parameter Discovery:

bash
# arjun
arjun -u https://target.com/page

# ParamSpider
python3 paramspider.py -d target.com

# ffuf
ffuf -u https://target.com/page?FUZZ=test -w parameters.txt -mc 200

JavaScript Analysis:

bash
# Extract JS files
echo "https://target.com" | hakrawler | grep "\.js$" | sort -u

# Analyze JS for secrets
cat file.js | grep -Eo "(api|token|key|secret|password)[\"']?\s*[:=]\s*[\"'][^\"']{10,}[\"']"

# LinkFinder
python3 linkfinder.py -i https://target.com/app.js -o results.html

# JSParser
python3 JSParser.py -u https://target.com
Show full SKILL.md (232 more words)Show less
4. Email/Phishing Reconnaissance

Email Format Detection:

bash
# Common formats
firstname.lastname@company.com
firstnamelastname@company.com
f.lastname@company.com
firstname@company.com

# Generate email list
# Tools: linkedin2username, namemash

Email Verification:

bash
# Check if email exists
# Tools: hunter.io, email-checker

# SMTP verification (careful - detectable)
telnet mail.company.com 25
VRFY user@company.com

Breached Credentials:

bash
# Have I Been Pwned
# Check if company emails in breaches

# dehashed.com
# Search for company domain

# WeLeakInfo alternatives
# pwndb (Tor)
5. Network Mapping

Identify Live Hosts:

bash
# Ping sweep
nmap -sn 10.10.10.0/24

# ARP scan (local network)
sudo arp-scan -l
sudo netdiscover -r 10.10.10.0/24

# fping
fping -a -g 10.10.10.0/24 2>/dev/null

Network Topology:

bash
# Traceroute
traceroute target.com
traceroute -T target.com  # TCP
traceroute -I target.com  # ICMP

# MTR (better traceroute)
mtr target.com

Firewall/IDS Detection:

bash
# Nmap firewall detection
nmap -sA target.com

# Check for filtered ports
nmap -p- -Pn target.com

# IDS evasion techniques
nmap -T2 -f target.com  # Slow scan, fragment packets
nmap -D RND:10 target.com  # Decoy scan
6-8. Cloud Assets, Vulnerability Scanning, and Credential Gathering

Exhaustive command catalogs for cloud storage discovery (S3/Azure/GCS), automated and targeted vulnerability scanning, and credential gathering have moved to references/cloud-vuln-credential-tooling.md.

9. Attack Surface Mapping

Comprehensive Enumeration:

bash
# Combination approach
1. Passive subdomain enum
2. Active subdomain bruteforce
3. Port scan all discovered hosts
4. Service enumeration
5. Web content discovery
6. Vulnerability scanning
7. Credential gathering

Automation Frameworks:

bash
# Amass + Nmap + Nuclei pipeline
amass enum -passive -d target.com -o subdomains.txt
cat subdomains.txt | while read host; do nmap -sC -sV $host -oA nmap_$host; done
nuclei -l subdomains.txt -t ~/nuclei-templates/

# Recon-ng
recon-ng
workspaces create target
modules load recon/domains-hosts/hackertarget
modules load recon/hosts-ports/shodan
10. Reporting and Documentation

Organize Findings:

bash
# Create project structure
mkdir -p target/{nmap,subdomains,web,creds,screenshots}

# Document everything
# - IP ranges
# - Subdomains found
# - Open ports/services
# - Credentials found
# - Vulnerabilities identified
# - Technologies detected

Essential Tools

Reconnaissance Suites:

  • Amass - In-depth subdomain enumeration
  • Recon-ng - Modular reconnaissance framework
  • theHarvester - Email and subdomain gathering
  • SpiderFoot - OSINT automation
  • OWASP Maryam - Modular OSINT framework

Subdomain Tools:

  • subfinder, assetfinder, findomain
  • Sublist3r, amass, gobuster dns

Port Scanners:

  • Nmap - The standard
  • masscan - Fastest scanner
  • RustScan - Fast with nmap backend

Web Tools:

  • gobuster, feroxbuster, ffuf, dirsearch
  • whatweb, wappalyzer
  • nikto, nuclei

Operational Security

Reconnaissance OPSEC:

bash
# Use VPN/Proxy
# Rate limit requests
# Randomize user agents
# Use passive methods when possible
# Don't leave obvious traces
# Respect robots.txt during testing phase

References

<!-- attack:start -->

ATT&CK Coverage

Generated from secskills-core/ttp-index.json — edit that file, then run python3 scripts/sync_attack.py --write. Re-verify IDs against the current ATT&CK release before citing them in a report.

Reconnaissance (TA0043)

  • T1589 Gather Victim Identity Information — see also performing-social-engineering
  • T1590 Gather Victim Network Information
  • T1591 Gather Victim Org Information — see also performing-social-engineering
  • T1592 Gather Victim Host Information
  • T1593 Search Open Websites/Domains
  • T1594 Search Victim-Owned Websites
  • T1595 Active Scanning — see also enumerating-network-services
  • T1596 Search Open Technical Databases

Detection content for any of these: engineering-detections. Proactive search: hunting-threats. Post-compromise: responding-to-incidents.

<!-- attack:end -->

© trilwu, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in secskills-offense/skills/performing-reconnaissance of trilwu/secskills.

  • SKILL.md
  • references/cloud-vuln-credential-tooling.md

Open the folder on GitHubat commit ca53957

Compare with similar skills

Performing Reconnaissance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Performing Reconnaissance compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Performing Reconnaissance this skilltrilwu/secskills157—~3.1kAutomated safety check: NotesMIT
Osint Methodologyelementalsouls/Claude-OSINT2.8k—~8.7kAutomated safety check: NotesMIT
Analysing Attacktsale/awesome-dfir-skills323—~1.4kAutomated safety check: PassApache-2.0
Implementing Attack Surface Managementmukul975/Anthropic-Cybersecurity-Skills34k—~1.8kAutomated safety check: PassApache-2.0
Recon Osinthypnguyen1209/offensive-claude388—~2.2kAutomated safety check: PassMIT
Wiki ReconEncod3d-Sec/TORCH329—~1.3kAutomated safety check: PassMIT

Similar skills

  • Osint Methodology

    elementalsouls/Claude-OSINT

    Comprehensive OSINT methodology for external red-team operations and authorized attack-surface assessments.

    2.8k GitHub stars~8.7k tokensUpdated today
    SecurityAuto-check: notes
  • Analysing Attack

    tsale/awesome-dfir-skills

    Analyse Mitre ATT&CK tactics, techniques and sub-techniques.

    323 GitHub stars~1.4k tokensUpdated 4 mo ago
    SecurityAuto-check passed
  • Implementing Attack Surface Management

    mukul975/Anthropic-Cybersecurity-Skills

    Implements external attack surface management (EASM) using Shodan, Censys, and ProjectDiscovery tools (subfinder, httpx, nuclei) for asset discovery, subdomain enumeration, service fingerprinting…

    34k GitHub stars~1.8k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Recon Osint

    hypnguyen1209/offensive-claude

    A skill your agent uses when mapping a target's external attack surface or gathering OSINT — subdomain enumeration, attack-surface mapping (httpx/katana/JS secrets), subdomain takeover…

    388 GitHub stars~2.2k tokensUpdated 12 days ago
    SecurityAuto-check passed
  • Wiki Recon

    Encod3d-Sec/TORCH

    External recon and OSINT pipeline - subdomain enum, live host discovery, URL crawl, JS analysis, nuclei scan.

    329 GitHub stars~1.3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Hardens code against vulnerabilities. An agent skill from penpot/penpot.

    61k GitHub starsUsed in 6 repos~4.7k tokens
    SecurityAuto-check: notes

More from trilwu/secskills

All 50 skills in this repo
  • Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.

    157 GitHub stars~3.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Securing AI Systems

    trilwu/secskills

    Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…

    157 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing Binaries

    trilwu/secskills

    Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.

    157 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing Go Binaries

    trilwu/secskills

    Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…

    157 GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing iOS Binaries

    trilwu/secskills

    Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…

    157 GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing Malware

    trilwu/secskills

    Analyze suspected malware safely — containment, static triage, sandboxed detonation, unpacking, capability and C2 extraction, IOC production, and YARA rule authoring.

    157 GitHub stars~3.6k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Performing Reconnaissance

What does Performing Reconnaissance do?

Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access. Performing Reconnaissance is an agent skill from trilwu/secskills. Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access.

When should I use Performing Reconnaissance?

Performing Reconnaissance fits situations like: gathering intelligence; mapping attack surface.

How do I install Performing Reconnaissance in Claude Code?

Run `npx skills add trilwu/secskills --skill performing-reconnaissance -a claude-code`. Or copy the skill folder (secskills-offense/skills/performing-reconnaissance in trilwu/secskills) into .claude/skills/performing-reconnaissance in your project. Claude Code loads it when a task matches its description.

How do I install Performing Reconnaissance in Codex?

Run `npx skills add trilwu/secskills --skill performing-reconnaissance -a codex`. Or copy the skill folder (secskills-offense/skills/performing-reconnaissance in trilwu/secskills) into .agents/skills/performing-reconnaissance in your project. Codex loads it when a task matches its description.

Can I use Performing Reconnaissance in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trilwu/secskills --skill performing-reconnaissance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/performing-reconnaissance, .gemini/skills/performing-reconnaissance, .github/skills/performing-reconnaissance and .opencode/skills/performing-reconnaissance in your project.

What does Performing Reconnaissance need to run?

Going by SKILL.md and its folder, Performing Reconnaissance needs the command-line tools its instructions call (python3, curl and jq). Our summary lists: Python 3.

Does Performing Reconnaissance access the network?

SKILL.md names 5 domains. In commands or code: crt.sh; the agent is likely to contact it when it follows the instructions. As links in the text: attack.mitre.org, github.com, owasp.org and book.hacktricks.xyz. This is read from the text; nothing was executed.

Is Performing Reconnaissance safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo; mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Performing Reconnaissance use?

Performing Reconnaissance is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Performing Reconnaissance use?

About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 744 tokens, read only when the agent opens those files.

What are the alternatives to Performing Reconnaissance?

Skills that share tags, products or a category with Performing Reconnaissance: Osint Methodology (elementalsouls/Claude-OSINT, 2.8k stars), Analysing Attack (tsale/awesome-dfir-skills, 323 stars), Implementing Attack Surface Management (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Recon Osint (hypnguyen1209/offensive-claude, 388 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Performing Reconnaissance?

trilwu (a GitHub user) maintains it in trilwu/secskills, which has 157 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on September 4, 2026.

Source: trilwu/secskills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.