Agent skill

Subdomain Enumeration

by uphiago in uphiago/recon-skills

Map subdomains via crt.sh and subfinder at recon kickoff. An agent skill from uphiago/recon-skills.

MITAuto-check passedSecurity

Install Subdomain Enumeration

skills CLI
$ npx skills add uphiago/recon-skills --skill subdomain-enumeration -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install uphiago/recon-skills subdomain-enumeration --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/uphiago/recon-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/recon/subdomain-enumeration .claude/skills/subdomain-enumeration && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
subdomain-enumeration
GitHub stars
1.3k
Token cost
~3.3k tokens
SKILL.md length
387 words
Files
1
Skills in repo
23
Repo updated
First seen
Licence
MIT

At a glance

Map subdomains via crt.sh and subfinder at recon kickoff. An agent skill from uphiago/recon-skills.

  • Works in 8 steps: Passive Enumeration (crt.sh + subfinder) → DNS Resolution → Live Host Discovery → …
  • Tasks that involve Bug bounty
  • SKILL.md covers When to Use, Prerequisites, How to Run and Quick Reference, plus 3 more sections
  • Calls curl, jq and wget; reaches crt.sh and crt.name

What it does

Subdomain Enumeration is an agent skill from uphiago/recon-skills. Map subdomains via crt.sh and subfinder at recon kickoff.

Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Requires curl, subfinder, httpx, dnsx, dig, jq

It sits in Security, covering Bug bounty. The repository describes itself as: Recon & pentest skill pack. CORS, XSS, SQLi, SSRF, RCE, WordPress, MCP, cloud, subdomain takeover, and more. Field-tested. MIT. Full write-up at hiago.sh. The licence is MIT.

When your agent uses it

  • Tasks that involve Bug bounty

Example prompts

  • “/subdomain-enumeration”

Requirements

  • Compatibility (from SKILL.md): Requires curl, subfinder, httpx, dnsx, dig, jq

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Passive Enumeration (crt.sh + subfinder)
  2. DNS Resolution
  3. Live Host Discovery
  4. Subdomain Categorization
  5. Subdomain Takeover Check
  6. Permutation & Prediction
  7. TLD Expansion
  8. Live Certificate Monitoring

What it can do on your machine

Read from SKILL.md and the folder at commit 1260244. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • jq
    • wget

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • crt.sh
    • crt.name
    • data.iana.org
    • hooks.slack.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires curl, subfinder, httpx, dnsx, dig, jq

    From compatibility in the SKILL.md frontmatter.

Context cost

Subdomain Enumeration loads about 3.3k tokens when it runs. Until then it costs about 20 tokens; SKILL.md has 387 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~20
When it runs · the whole SKILL.md, loaded when a task matches
~3.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from uphiago/recon-skills at commit 1260244, republished under its MIT licence (© uphiago). 387 words, ~3,300 tokens.

Download SKILL.mdSave it as .claude/skills/subdomain-enumeration/SKILL.md (or your agent's skills folder).
name
subdomain-enumeration
description
Map subdomains via crt.sh and subfinder at recon kickoff.
compatibility
Requires curl, subfinder, httpx, dnsx, dig, jq
version
1.1.0
revision_date
2026-07-25
license
MIT
platforms
linux
tags
recon, subdomain, DNS, crt.sh, asset-discovery
category
recon
related_skills
wp-mass-recon, staging-subdomain-hunt, deep-invade, recon-playbook

Subdomain Enumeration Skill

Comprehensive subdomain discovery using certificate transparency logs (crt.sh), DNS brute force, and passive sources. The first step in any recon pipeline — you can't attack what you don't know exists. Subdomain enumeration consistently reveals staging environments, internal admin panels, API gateways, and forgotten WordPress installs that are softer targets than the production site.

When to Use

  • Starting recon on any target domain.
  • Production site is well-secured — find softer entry points.
  • After skill_view(name='wp-mass-recon') — enumerate subdomains for each WordPress target.
  • Building a complete asset inventory for a target organization.

Prerequisites

  • curl, httpx, dig, jq, dnsx, and subfinder.
  • A DNS brute-force wordlist, supplied by the operator.
  • Approval to disclose the domain to third-party passive sources such as crt.sh, crt.name, and subfinder providers.

How to Run

bash
DOMAIN="${1:-example.com}"
OUTPUT_ROOT="${OUTPUT_DIR:-./output}"
OUTDIR="$OUTPUT_ROOT/subdomains/$DOMAIN"

if [[ ! "$DOMAIN" =~ ^[A-Za-z0-9.-]+$ ]]; then
  echo "Invalid domain: $DOMAIN" >&2
  exit 2
fi

mkdir -p "$OUTDIR"

# Passive: crt.sh (retry: it frequently returns 502 while its database refreshes)
for attempt in 1 2 3; do
  curl -fsS --max-time 30 --connect-timeout 10 \
    "https://crt.sh/?q=%25.$DOMAIN&output=json" -o "$OUTDIR/crtsh_raw.json" && break
  sleep 15
done
jq -r '.[].name_value' "$OUTDIR/crtsh_raw.json" 2>/dev/null \
  | sed 's/\*\.//g' \
  | sort -u > "$OUTDIR/crtsh.txt"
# If crt.sh stays down, crtsh.txt ends up empty: keep going with crt.name/subfinder.

# crt.name (historical CT data; resolve names before probing)
curl -fsS --max-time 30 --connect-timeout 10 "https://crt.name/v1/search?apex=$DOMAIN" \
  | sed 's/\r$//' \
  | sed 's/^\*\.//' \
  | sort -u > "$OUTDIR/crtname.txt"

# Passive: subfinder
subfinder -d "$DOMAIN" -silent -timeout 30 > "$OUTDIR/subfinder.txt"

# Merge and deduplicate
cat "$OUTDIR/crtsh.txt" "$OUTDIR/crtname.txt" "$OUTDIR/subfinder.txt" \
  | grep -E '^[A-Za-z0-9.-]+\.[A-Za-z]{2,}$' \
  | sort -u > "$OUTDIR/all_subs.txt"

# Probe live hosts
httpx -silent -l "$OUTDIR/all_subs.txt" -threads 50 -rate-limit 2 \
  -status-code -tech-detect -title -o "$OUTDIR/alive.txt"

Quick Reference

SourceMethodCoverageSpeed
crt.shCertificate transparencyExcellent (most certs)Fast (1-5s)
subfinderPassive APIs (VirusTotal, Shodan, DNSdumpster, etc.)Very goodFast (30-60s)
dnsxBulk DNS A/AAAA/CNAME resolution (100x faster than dig)Good (uncovers non-HTTP)Fast (10-30s)
httpx probeLive HTTP/HTTPS checkBest for web attack surfaceFast (30-60s)
Google dorksite:example.comSupplementalManual

Procedure

Step 1 — Passive Enumeration (crt.sh + subfinder)
bash
DOMAIN="$1"
OUTPUT_ROOT="${OUTPUT_DIR:-./output}"
OUTDIR="$OUTPUT_ROOT/subdomains/$DOMAIN"

if [[ ! "$DOMAIN" =~ ^[A-Za-z0-9.-]+$ ]]; then
  echo "Invalid domain: $DOMAIN" >&2
  exit 2
fi

mkdir -p "$OUTDIR"

echo "[*] Passive enumeration for $DOMAIN..."

# crt.sh — certificate transparency logs (retry: it frequently returns 502 while its database refreshes)
echo "[*] crt.sh query..."
for attempt in 1 2 3; do
  curl -fsS --max-time 30 --connect-timeout 10 \
    "https://crt.sh/?q=%25.$DOMAIN&output=json" -o "$OUTDIR/crtsh_raw.json" 2>/dev/null && break
  sleep 15
done
jq -r '.[].name_value' "$OUTDIR/crtsh_raw.json" 2>/dev/null | \
  sed 's/\*\.//g' | \
  sed 's/^www\.//' | \
  sort -u > "$OUTDIR/crtsh.txt"

crt_count=$(wc -l < "$OUTDIR/crtsh.txt")
echo "  crt.sh: $crt_count entries"
if [[ ! -s "$OUTDIR/crtsh.txt" ]]; then
  echo "  [!] crt.sh unavailable or empty after retries; results are incomplete" >&2
fi

# crt.name — historical certificate-transparency data
echo "[*] crt.name query..."
curl -fsS --max-time 30 --connect-timeout 10 "https://crt.name/v1/search?apex=$DOMAIN" 2>/dev/null | \
  sed 's/\r$//' | \
  sed 's/^\*\.//' | \
  sort -u > "$OUTDIR/crtname.txt"
crtname_count=$(wc -l < "$OUTDIR/crtname.txt")
echo "  crt.name: $crtname_count entries (historical; resolve before probing)"

# Also query with %25. (wildcard)
for attempt in 1 2 3; do
  curl -fsS --max-time 30 --connect-timeout 10 \
    "https://crt.sh/?q=%25.%25.$DOMAIN&output=json" -o "$OUTDIR/crtsh_wildcard_raw.json" 2>/dev/null && break
  sleep 15
done
jq -r '.[].name_value' "$OUTDIR/crtsh_wildcard_raw.json" 2>/dev/null | \
  sed 's/\*\.//g' | \
  sort -u > "$OUTDIR/crtsh_wildcard.txt"

# subfinder — passive API aggregation
echo "[*] subfinder..."
subfinder -d "$DOMAIN" -silent -timeout 30 2>/dev/null | sort -u > "$OUTDIR/subfinder.txt"
subf_count=$(wc -l < "$OUTDIR/subfinder.txt")
echo "  subfinder: $subf_count entries"

# Merge all passive sources
cat "$OUTDIR"/crtsh.txt "$OUTDIR"/crtsh_wildcard.txt "$OUTDIR"/crtname.txt "$OUTDIR"/subfinder.txt 2>/dev/null | \
  sed 's/^www\.//' | \
  grep -E '^[a-zA-Z0-9.-]+\.[a-zA-Z]{2,}$' | \
  sort -u > "$OUTDIR/all_passive.txt"

total=$(wc -l < "$OUTDIR/all_passive.txt")
echo ""
echo "[+] Total unique subdomains (passive): $total"
Step 2 — DNS Resolution
bash
DOMAIN="$1"
OUTPUT_ROOT="${OUTPUT_DIR:-./output}"
OUTDIR="$OUTPUT_ROOT/subdomains/$DOMAIN"

echo "[*] Resolving subdomains..."

# Batch resolve with dnsx (100x faster than dig loop)
dnsx -silent -l "$OUTDIR/all_passive.txt" -a -resp-only -o "$OUTDIR/resolved_raw.txt" 2>/dev/null
# Format output: subdomain => IP
while read -r line; do
  sub=$(echo "$line" | cut -d' ' -f1)
  ip=$(echo "$line" | cut -d' ' -f2)
  echo "$sub => $ip"
done < "$OUTDIR/resolved_raw.txt" > "$OUTDIR/resolved.txt"

resolved=$(wc -l < "$OUTDIR/resolved.txt")
echo "[+] $resolved subdomains resolved to IPs"

# Count unique IPs
unique_ips=$(awk '{print $3}' "$OUTDIR/resolved.txt" | sort -u | wc -l)
echo "[+] $unique_ips unique IPs"

# Identify shared hosting (many subdomains → same IP)
echo ""
echo "[*] Shared hosting clusters:"
awk '{print $3}' "$OUTDIR/resolved.txt" | sort | uniq -c | sort -rn | head -10 | while read -r count ip; do
  [[ "$count" -gt 1 ]] && echo "  $ip: $count subdomains"
done
Step 3 — Live Host Discovery
bash
DOMAIN="$1"
OUTPUT_ROOT="${OUTPUT_DIR:-./output}"
OUTDIR="$OUTPUT_ROOT/subdomains/$DOMAIN"

echo "[*] Probing live hosts..."

# httpx with tech detection
httpx -silent -l "$OUTDIR/all_passive.txt" -threads 50 \
  -status-code -tech-detect -title -location \
  -o "$OUTDIR/alive.txt" 2>/dev/null

alive=$(wc -l < "$OUTDIR/alive.txt")
echo "[+] $alive live hosts"

# Categorize by status code
echo ""
echo "[*] By HTTP status:"
echo "  200: $(grep -c '\[200\]' "$OUTDIR/alive.txt")"
echo "  301/302: $(grep -cE '\[301\]|\[302\]' "$OUTDIR/alive.txt")"
echo "  403: $(grep -c '\[403\]' "$OUTDIR/alive.txt")"
echo "  404: $(grep -c '\[404\]' "$OUTDIR/alive.txt")"

# Categorize by technology
echo ""
echo "[*] By technology:"
grep -Eo '\[[a-z-]+\]' "$OUTDIR/alive.txt" | tr -d '[]' | sort | uniq -c | sort -rn | head -15

# WordPress subdomains
echo ""
echo "[*] WordPress subdomains:"
grep -i 'wordpress' "$OUTDIR/alive.txt" | awk '{print $1}' | head -10

# Non-HTTP services (from DNS resolution)
echo ""
echo "[*] Interesting non-standard ports from DNS (MX, NS, etc.):"
dig +short "$DOMAIN" MX 2>/dev/null | head -5
dig +short "$DOMAIN" NS 2>/dev/null | head -5
dig +short "$DOMAIN" TXT 2>/dev/null | grep -i 'spf\|v=spf' | head -3
Step 4 — Subdomain Categorization
bash
DOMAIN="$1"
OUTPUT_ROOT="${OUTPUT_DIR:-./output}"
OUTDIR="$OUTPUT_ROOT/subdomains/$DOMAIN"

echo "[*] Categorizing subdomains..."

# Staging/Dev
echo ""
echo "=== STAGING / DEV ==="
grep -iE 'staging|stage|dev\.|development|test|uat|beta|sandbox|preview|qa' "$OUTDIR/all_passive.txt"

# Admin/Internal
echo ""
echo "=== ADMIN / INTERNAL ==="
grep -iE 'admin|portal|internal|dashboard|manage|cp\.|control|panel|cpanel|webmail|mail\.' "$OUTDIR/all_passive.txt"

# API
echo ""
echo "=== API ==="
grep -iE 'api|rest|graphql|ws\.|websocket' "$OUTDIR/all_passive.txt"

# Infrastructure
echo ""
echo "=== CDN / STATIC ==="
grep -iE 'cdn|static|assets|media|img|images|files|download|origin|proxy' "$OUTDIR/all_passive.txt"

# Email
echo ""
echo "=== EMAIL ==="
grep -iE 'mail\.|smtp|imap|pop|email|webmail|autodiscover' "$OUTDIR/all_passive.txt"

# Cloud
echo ""
echo "=== CLOUD ==="
grep -iE 'aws|azure|gcp|cloud|s3|bucket|firebase' "$OUTDIR/all_passive.txt"

# Legacy
echo ""
echo "=== LEGACY / OLD ==="
grep -iE 'old|old\.|v1|v2|legacy|archive|backup|bak' "$OUTDIR/all_passive.txt"
Step 5 — Subdomain Takeover Check
bash
DOMAIN="$1"
OUTPUT_ROOT="${OUTPUT_DIR:-./output}"
OUTDIR="$OUTPUT_ROOT/subdomains/$DOMAIN"

echo "[*] Checking for subdomain takeover opportunities..."

# Check for dangling CNAMEs (subdomains pointing to non-existent services)
# For bulk CNAME check: dnsx -silent -l all_passive.txt -cname -resp-only
while read -r sub; do
  cname=$(dig +short "$sub" CNAME 2>/dev/null)
  if [[ -n "$cname" ]]; then
    # Check if the CNAME target resolves
    cname_ip=$(dig +short "$cname" A 2>/dev/null)
    if [[ -z "$cname_ip" ]]; then
      echo "[TAKEOVER?] $sub => $cname (NOT RESOLVING)"

      # Identify provider from CNAME
      if echo "$cname" | grep -qi 'amazonaws.com'; then
        echo "  Provider: AWS (S3/CloudFront) — check if bucket/domain is claimable"
      elif echo "$cname" | grep -qi 'azure'; then
        echo "  Provider: Azure — check if resource is claimable"
      elif echo "$cname" | grep -qi 'github.io'; then
        echo "  Provider: GitHub Pages — check if repo name is available"
      elif echo "$cname" | grep -qi 'herokuapp.com'; then
        echo "  Provider: Heroku — check if app name is available"
      elif echo "$cname" | grep -qi 'vercel-dns.com'; then
        echo "  Provider: Vercel — check if project is claimable"
      elif echo "$cname" | grep -qi 'zendesk.com'; then
        echo "  Provider: Zendesk — check if help desk is claimable"
      fi
    fi
  fi
  sleep 0.5
done < "$OUTDIR/all_passive.txt"
Show full SKILL.md (182 more words)Show less

Pitfalls

  • crt.sh rate limiting. crt.sh may return empty JSON if rate-limited. Use delays or query the PostgreSQL dump directly.
  • subfinder requires API keys. Some sources (VirusTotal, Shodan) require API keys in ~/.config/subfinder/provider-config.yaml. Without them, results are limited.
  • Wildcard DNS. If *.example.com resolves to the same IP, all subdomains will appear "live" in httpx. Check for wildcard by resolving a random string: dig RANDOMSTRING.example.com.
  • Cloudflare proxying. Subdomains behind Cloudflare will show Cloudflare IPs, not origin IPs. Use SecurityTrails or DNSDumpster for historical DNS records.

Verification

  • Every subdomain MUST be probed with httpx to confirm it serves HTTP/HTTPS.
  • Resolved IPs MUST be cross-referenced with known CDN IPs (Cloudflare, CloudFront, Fastly) to avoid mistaking CDN IPs for origin.
  • Subdomain takeover candidates MUST have their CNAME target manually verified as unclaimed.
  • All live subdomains should be documented with: URL, HTTP status, technology stack, and page title.
Phase 7 — Permutation & Prediction

Generate smart mutations from already-discovered subdomains to find hidden services:

bash
# gotator — generates permutations
gotator -sub all_subs.txt -perm permutations.txt -depth 1 -numbers 3 -md | sort -u > subs_permuted.txt

# Resolve permutations
puredns resolve subs_permuted.txt -r resolvers.txt -o subs_permuted_alive.txt

# Common permutation patterns for the wordlist
# %s-dev, dev-%s, %s-staging, staging-%s, %s-prod, %s-internal
# %s-admin, admin-%s, %s-api, api-%s, %s-test, test-%s
# %s-stg, stg-%s, %s-uat, uat-%s, %s-www, www-%s
Phase 8 — TLD Expansion

A company that owns target.com often neglects target.io, target.net, target.xyz:

bash
# tldbrute — discovers registered TLD variants
tldbrute -d target.com

# Manual IANA TLD list approach
wget -q https://data.iana.org/TLD/tlds-alpha-by-domain.txt
ROOT=$(echo "target.com" | cut -d. -f1)
cat tlds-alpha-by-domain.txt | tr '[:upper:]' '[:lower:]' \
  | while read tld; do echo "$ROOT.$tld"; sleep 0.2; done \
  | httpx -silent -mc 200 > tlds_alive.txt

# Expand existing subdomains across TLDs
cat all_subs.txt | while read sub; do
  cat tlds-alpha-by-domain.txt | tr '[:upper:]' '[:lower:]' \
    | sed "s/^/$sub./"
done | dnsx -silent > subs_tld_expanded.txt
Phase 9 — Live Certificate Monitoring

Catch new subdomains the moment they're issued:

bash
# gungnir — real-time certificate transparency monitoring
gungnir -d target.com

# certwatcher — alternative CT log monitor
certwatcher -d target.com --webhook https://hooks.slack.com/xxx

© uphiago, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in recon/subdomain-enumeration of uphiago/recon-skills.

Open the folder on GitHubat commit 1260244

Compare with similar skills

Subdomain Enumeration next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Subdomain Enumeration compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Subdomain Enumeration this skilluphiago/recon-skills1.3k—~3.3kAutomated safety check: PassMIT
Web3 Smart Contract Auditawarexone/Agentic-Bug-Hunter5.3k3 repos~4.5kAutomated safety check: PassMIT
Bug Bounty Hunting Methodologyawarexone/Agentic-Bug-Hunter5.3k2 repos~4.7kAutomated safety check: PassMIT
Metabigor OSINT Reconj3ssie/metabigor1.8k—~2.4kAutomated safety check: PassMIT
Wooyun Legacytanweai/wooyun-legacy1.8k—~1.9kAutomated safety check: PassCustom licence
Client Request Signature Reversalawarexone/Agentic-Bug-Hunter5.3k—~4.7kAutomated safety check: PassMIT

Similar skills

  • Web3 Smart Contract Audit

    awarexone/Agentic-Bug-Hunter

    Guides smart contract audits and bounty target selection with ten DeFi bug classes, kill signals, a Foundry PoC template and grep patterns.

    5.3k GitHub starsUsed in 3 repos~4.5k tokens
    SecurityAuto-check passed
  • Bug Bounty Hunting Methodology

    awarexone/Agentic-Bug-Hunter

    Orchestrates a bug bounty session with a 5-phase workflow and a critical-thinking framework covering developer psychology, anomaly detection and What-If experiments.

    5.3k GitHub starsUsed in 2 repos~4.7k tokens
    SecurityAuto-check passed
  • Metabigor OSINT Recon

    j3ssie/metabigor

    Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys.

    1.8k GitHub stars~2.4k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Wooyun Legacy

    tanweai/wooyun-legacy

    WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…

    1.8k GitHub stars~1.9k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Client Request Signature Reversal

    awarexone/Agentic-Bug-Hunter

    Recovers a client-side request signature or anti-bot token just far enough to replay blocked requests in bug bounty testing, starting from a captured packet.

    5.3k GitHub stars~4.7k tokensUpdated today
    SecurityAuto-check passed
  • Web3 Bug Bounty AI Tools

    tradecatlabs/vibe-coding-cn

    A selection guide to AI-driven tools for Web3 bug bounty work, from autonomous web pentesters to smart contract bug finders, with notes on authorization.

    17k GitHub starsUsed in 2 repos~3.9k tokens
    SecurityAuto-check: warnings

More from uphiago/recon-skills

All 23 skills in this repo
  • Flags API endpoints whose data or actions look like they should need a login but currently don't, as part of authorized security testing.

    1.3k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed
  • Error Log Mining

    uphiago/recon-skills

    Mine errorlog for creds, paths, SQL when leak hunt finds. An agent skill from uphiago/recon-skills.

    1.3k GitHub stars~3.3k tokensUpdated 1 mo ago
    Auto-check passed
  • JS Secrets Extraction

    uphiago/recon-skills

    Analyze JS bundles and source maps for hardcoded secrets, API keys, JWTs, and internal endpoints

    1.3k GitHub stars~2.6k tokensUpdated 1 mo ago
    Auto-check passed
  • Recon Playbook

    uphiago/recon-skills

    A skill your agent uses when starting or restructuring an authorized external web and API assessment.

    1.3k GitHub stars~1.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Web Enumeration

    uphiago/recon-skills

    Sensitive file scanning, path traversal bypass, vHost enum, .env extract, log mining, Varnish detect

    1.3k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check: notes
  • 401 403 Bypass Techniques

    uphiago/recon-skills

    A skill your agent uses when protected HTTP routes return 401 or 403.

    1.3k GitHub stars~3.1k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Subdomain Enumeration

What does Subdomain Enumeration do?

Map subdomains via crt.sh and subfinder at recon kickoff. An agent skill from uphiago/recon-skills. Subdomain Enumeration is an agent skill from uphiago/recon-skills.sh and subfinder at recon kickoff.

When should I use Subdomain Enumeration?

Subdomain Enumeration fits situations like: tasks that involve Bug bounty.

How do I install Subdomain Enumeration in Claude Code?

Run `npx skills add uphiago/recon-skills --skill subdomain-enumeration -a claude-code`. Or copy the skill folder (recon/subdomain-enumeration in uphiago/recon-skills) into .claude/skills/subdomain-enumeration in your project. Claude Code loads it when a task matches its description.

How do I install Subdomain Enumeration in Codex?

Run `npx skills add uphiago/recon-skills --skill subdomain-enumeration -a codex`. Or copy the skill folder (recon/subdomain-enumeration in uphiago/recon-skills) into .agents/skills/subdomain-enumeration in your project. Codex loads it when a task matches its description.

Can I use Subdomain Enumeration in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add uphiago/recon-skills --skill subdomain-enumeration -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/subdomain-enumeration, .gemini/skills/subdomain-enumeration, .github/skills/subdomain-enumeration and .opencode/skills/subdomain-enumeration in your project.

What does Subdomain Enumeration need to run?

Going by SKILL.md and its folder, Subdomain Enumeration needs the command-line tools its instructions call (curl, jq and wget). Compatibility (from SKILL.md): Requires curl, subfinder, httpx, dnsx, dig, jq.

Does Subdomain Enumeration access the network?

SKILL.md names 4 domains. In commands or code: crt.sh, crt.name, data.iana.org and hooks.slack.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Subdomain Enumeration safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Subdomain Enumeration use?

Subdomain Enumeration is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Subdomain Enumeration use?

About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Subdomain Enumeration?

Skills that share tags, products or a category with Subdomain Enumeration: Web3 Smart Contract Audit (awarexone/Agentic-Bug-Hunter, 5.3k stars), Bug Bounty Hunting Methodology (awarexone/Agentic-Bug-Hunter, 5.3k stars), Metabigor OSINT Recon (j3ssie/metabigor, 1.8k stars) and Wooyun Legacy (tanweai/wooyun-legacy, 1.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Subdomain Enumeration?

uphiago (a GitHub user) maintains it in uphiago/recon-skills, which has 1,293 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on September 1, 2026.

Source: uphiago/recon-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.