Agent skill

Visual Recon

by uphiago in uphiago/recon-skills

Screenshot all live hosts for rapid visual triage and technology fingerprinting.

MITAuto-check passedSecurity

Install Visual Recon

skills CLI
$ npx skills add uphiago/recon-skills --skill visual-recon -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install uphiago/recon-skills visual-recon --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/uphiago/recon-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/recon/visual-recon .claude/skills/visual-recon && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
visual-recon
GitHub stars
1.3k
Token cost
~1.5k tokens
SKILL.md length
388 words
Files
1
Skills in repo
23
Repo updated
First seen
Licence
MIT

At a glance

Screenshot all live hosts for rapid visual triage and technology fingerprinting.

  • Works in 6 steps: Mass Screenshot Capture → Headless Mode for JS-Rendered Sites → Visual Analysis Patterns → …
  • Tasks that involve Bug bounty
  • SKILL.md covers When to Use, Prerequisites, Quick Start and Procedure, plus 3 more sections
  • Calls python3 and go

What it does

Visual Recon is an agent skill from uphiago/recon-skills. Screenshot all live hosts for rapid visual triage and technology fingerprinting.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Requires curl, httpx, python3

It sits in Security, covering Bug bounty. It works with WordPress. The repository describes itself as: Recon & pentest skill pack. CORS, XSS, SQLi, SSRF, RCE, WordPress, MCP, cloud, subdomain takeover, and more. Field-tested. MIT. Full write-up at hiago.sh. The licence is MIT.

When your agent uses it

  • Tasks that involve Bug bounty

Example prompts

  • “/visual-recon”

Requirements

  • Python 3
  • Compatibility (from SKILL.md): Requires curl, httpx, python3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Mass Screenshot Capture
  2. Headless Mode for JS-Rendered Sites
  3. Visual Analysis Patterns
  4. Visual Diffing (Multi-Environment)
  5. Technology Fingerprinting from Screenshots
  6. Screenshot-Based Triage Pipeline

What it can do on your machine

Read from SKILL.md and the folder at commit 1260244. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3
    • go

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires curl, httpx, python3

    From compatibility in the SKILL.md frontmatter.

Context cost

Visual Recon loads about 1.5k tokens when it runs. Until then it costs about 23 tokens; SKILL.md has 388 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~23
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from uphiago/recon-skills at commit 1260244, republished under its MIT licence (© uphiago). 388 words, ~1,540 tokens.

Download SKILL.mdSave it as .claude/skills/visual-recon/SKILL.md (or your agent's skills folder).
name
visual-recon
description
Screenshot all live hosts for rapid visual triage and technology fingerprinting.
compatibility
Requires curl, httpx, python3
version
1.1.0
revision_date
2026-07-25
license
MIT
platforms
linux
tags
recon, screenshot, visual, triage, fingerprinting, technology
category
recon
related_skills
subdomain-enumeration, web-enumeration, cms-detection, port-service-discovery

Visual Recon

Automatically screenshot every live host to triage hundreds of subdomains visually instead of manually opening each one. Combined with technology fingerprinting, this reveals technology stacks, default CMS install pages, admin panels, and misconfigured services at a glance. Process 500+ hosts in minutes and identify high-value targets by visual inspection.

When to Use

  • You have 100+ live subdomains and need to prioritize targets quickly.
  • Manual browsing is too slow for bulk reconnaissance.
  • Need to identify default install pages (WordPress setup, phpMyAdmin login, Jenkins dashboard).
  • Want to compare visual fingerprints across subdomains (shared infrastructure).
  • Target serves different content based on User-Agent or geolocation.

Prerequisites

  • terminal gowitness, httpx, and curl.
  • gowitness installed: go install github.com/sensepost/gowitness@latest.
  • A list of alive subdomains from subdomain-enumeration.

Quick Start

bash
gowitness file -f alive_subs.txt -P ./screenshots/ --no-http

Procedure

Phase 1 — Mass Screenshot Capture
bash
# gowitness — fast, Go-based screenshot tool
gowitness file -f alive_subs.txt \
  -P ./screenshots/ \
  --no-http \
  --timeout 15 \
  --resolution-x 1440 \
  --resolution-y 900

# With database for searchable results
gowitness file -f alive_subs.txt -P ./screenshots/ --no-http \
  --db gowitness.db --chrome-window-x 1440 --chrome-window-y 900

# Query results
gowitness report list --db gowitness.db
gowitness report generate --db gowitness.db

# eyewitness — with HTML report generation
python3 EyeWitness.py \
  -f alive_subs.txt \
  --web \
  -d ./eyewitness_output/ \
  --timeout 15 \
  --no-prompt
Phase 2 — Headless Mode for JS-Rendered Sites
bash
# Single-page applications need JS execution
gowitness single -u https://[SPA_COMPANY] \
  -P ./screenshots/ \
  --chrome-window-x 1440 --chrome-window-y 900

# Batch headless capture
cat spa_urls.txt | while read url; do
  gowitness single -u "$url" -P ./screenshots/
done
Phase 3 — Visual Analysis Patterns

Review screenshots for high-value patterns:

bash
# Extract all titles from screenshots for quick filtering
gowitness report list --db gowitness.db \
  | grep -iE "login|admin|dashboard|setup|install|phpmyadmin|jenkins|grafana|api|dev|staging|test"

# Look for default error pages (identifies specific web servers)
gowitness report list --db gowitness.db \
  | grep -iE "404|403|502|503|default|maintenance|under construction"

What to look for:

Screenshot showsMeaning
WordPress install pageFresh WordPress — test registration on /wp-admin/install.php
phpMyAdmin loginDatabase access panel — try default creds
Jenkins loginCI/CD server — check for unauthenticated access
Grafana/PrometheusMonitoring dashboard — check for public data
IIS default pageWindows server — check for ASP.NET endpoints
Apache default pageStandard Linux server — check for server-status
Error stack tracesDebug mode enabled — extract server paths and versions
Directory listingReadable file tree — check for config files
Login form on custom portInternal admin panel — highest priority target
Show full SKILL.md (154 more words)Show less
Phase 4 — Visual Diffing (Multi-Environment)
bash
# Compare screenshots across subdomains to find shared infrastructure
# Same visual = shared server = if one is vulnerable, all are

ls screenshots/ | cut -d'-' -f1 | sort | uniq -c | sort -rn
# High count of identical-looking sites = mass vulnerability potential
Phase 5 — Technology Fingerprinting from Screenshots
bash
# whatweb — identifies CMS, frameworks, servers
whatweb -i alive_subs.txt -a 3 -t 50 --log-brief=cms_results.txt

# wappalyzer CLI — detailed tech stack
wappalyzer https://target.com

# httpx with tech detection built-in
cat alive_subs.txt | httpx -silent -tech-detect -o tech_detected.txt

# Extract unique technologies
cat tech_detected.txt | awk -F'[' '{print $2}' | tr -d ']' | tr ',' '\n' \
  | sort | uniq -c | sort -rn
Phase 6 — Screenshot-Based Triage Pipeline
bash
# Full pipeline: subdomains → alive → screenshot → filter → prioritize
cat all_subs.txt \
  | httpx -silent -mc 200 -o alive_200.txt

gowitness file -f alive_200.txt -P ./screenshots/ --no-http

# Generate report for manual review
gowitness report generate --db gowitness.db -o ./report/

# Extract login/admin pages for priority testing
gowitness report list --db gowitness.db \
  | grep -iE "login|admin|sign.?in|dashboard|panel|manage" \
  > priority_targets.txt

Pitfalls

  • Large screenshot batches can overwhelm disk. 500 screenshots at 1440x900 ≈ 300MB.
  • JS-heavy SPAs may render as blank. Use headless mode with longer timeout.
  • Redirect chains produce screenshots of the redirect target. This is correct — you want the final destination.
  • CAPTCHA pages waste screenshots. Filter CAPTCHA hosts before screenshotting.
  • Timeout on slow servers. --timeout 15 is usually sufficient; increase for slow connections.

Verification

  1. Screenshots exist for all hosts in alive_subs.txt.
  2. Visual inspection confirms each screenshot shows meaningful content (not blank, not error).
  3. Technology detection matches the visual fingerprint (WordPress favicon = WordPress CMS).
  4. Priority targets (login panels, admin dashboards, dev environments) are identified and moved to next phase.
  • subdomain-enumeration — Generate the list of alive subdomains.
  • web-enumeration — Deep dive into individual hosts found via screenshots.
  • cms-detection — Automated CMS and framework detection on discovered hosts.

© uphiago, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in recon/visual-recon of uphiago/recon-skills.

Open the folder on GitHubat commit 1260244

Compare with similar skills

Visual Recon next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Visual Recon compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Visual Recon this skilluphiago/recon-skills1.3k—~1.5kAutomated safety check: PassMIT
Web ReconCommonHuman-Lab/nyxstrike156—~907Automated safety check: PassCustom licence
Hunt Auth Bypasselementalsouls/Claude-BugHunter4.8k—~8.2kAutomated safety check: PassMIT
Hunt Business Logicmajiayu000/claude-skill-registry6662 repos~4.4kAutomated safety check: PassMIT
Web3 Smart Contract Auditawarexone/Agentic-Bug-Hunter5.3k3 repos~4.5kAutomated safety check: PassMIT
Add Partial Reconsamugit83/redamon2.9k—~1.1kAutomated safety check: PassMIT

Similar skills

  • Web Recon

    CommonHuman-Lab/nyxstrike

    Web content discovery and technology fingerprinting using gobuster, ffuf, feroxbuster, katana, httpx, and wafw00f

    156 GitHub stars~907 tokensUpdated today
    SecurityAuto-check passed
  • Hunt Auth Bypass

    elementalsouls/Claude-BugHunter

    Hunting skill for auth bypass vulnerabilities. An agent skill from elementalsouls/Claude-BugHunter.

    4.8k GitHub stars~8.2k tokensUpdated yesterday
    SecurityAuto-check passed
  • Hunt Business Logic

    majiayu000/claude-skill-registry

    Hunting skill for business logic vulnerabilities. An agent skill from majiayu000/claude-skill-registry.

    666 GitHub starsUsed in 2 repos~4.4k tokens
    SecurityAuto-check passed
  • Web3 Smart Contract Audit

    awarexone/Agentic-Bug-Hunter

    Guides smart contract audits and bounty target selection with ten DeFi bug classes, kill signals, a Foundry PoC template and grep patterns.

    5.3k GitHub starsUsed in 3 repos~4.5k tokens
    SecurityAuto-check passed
  • Add Partial Recon

    samugit83/redamon

    Adding partial-recon support for a tool: running a single pipeline phase on demand from the workflow graph, reading its inputs from the existing Neo4j graph and merging results back.

    2.9k GitHub stars~1.1k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Flounder

    adshao/flounder

    Operates Flounder, an autonomous white-hat security auditor.

    517 GitHub stars~9.2k tokensUpdated 2 days ago
    SecurityAuto-check passed

More from uphiago/recon-skills

All 23 skills in this repo
  • Flags API endpoints whose data or actions look like they should need a login but currently don't, as part of authorized security testing.

    1.3k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed
  • Error Log Mining

    uphiago/recon-skills

    Mine errorlog for creds, paths, SQL when leak hunt finds. An agent skill from uphiago/recon-skills.

    1.3k GitHub stars~3.3k tokensUpdated 1 mo ago
    Auto-check passed
  • JS Secrets Extraction

    uphiago/recon-skills

    Analyze JS bundles and source maps for hardcoded secrets, API keys, JWTs, and internal endpoints

    1.3k GitHub stars~2.6k tokensUpdated 1 mo ago
    Auto-check passed
  • Recon Playbook

    uphiago/recon-skills

    A skill your agent uses when starting or restructuring an authorized external web and API assessment.

    1.3k GitHub stars~1.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Web Enumeration

    uphiago/recon-skills

    Sensitive file scanning, path traversal bypass, vHost enum, .env extract, log mining, Varnish detect

    1.3k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check: notes
  • 401 403 Bypass Techniques

    uphiago/recon-skills

    A skill your agent uses when protected HTTP routes return 401 or 403.

    1.3k GitHub stars~3.1k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Categories

Questions about Visual Recon

What does Visual Recon do?

Screenshot all live hosts for rapid visual triage and technology fingerprinting. Visual Recon is an agent skill from uphiago/recon-skills. Screenshot all live hosts for rapid visual triage and technology fingerprinting.

When should I use Visual Recon?

Visual Recon fits situations like: tasks that involve Bug bounty.

How do I install Visual Recon in Claude Code?

Run `npx skills add uphiago/recon-skills --skill visual-recon -a claude-code`. Or copy the skill folder (recon/visual-recon in uphiago/recon-skills) into .claude/skills/visual-recon in your project. Claude Code loads it when a task matches its description.

How do I install Visual Recon in Codex?

Run `npx skills add uphiago/recon-skills --skill visual-recon -a codex`. Or copy the skill folder (recon/visual-recon in uphiago/recon-skills) into .agents/skills/visual-recon in your project. Codex loads it when a task matches its description.

Can I use Visual Recon in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add uphiago/recon-skills --skill visual-recon -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/visual-recon, .gemini/skills/visual-recon, .github/skills/visual-recon and .opencode/skills/visual-recon in your project.

What does Visual Recon need to run?

Going by SKILL.md and its folder, Visual Recon needs the command-line tools its instructions call (python3 and go). Our summary lists: Python 3. Compatibility (from SKILL.md): Requires curl, httpx, python3.

Does Visual Recon access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Visual Recon safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Visual Recon use?

Visual Recon is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Visual Recon use?

About 1.5k tokens (SKILL.md is roughly 6.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Visual Recon?

Skills that share tags, products or a category with Visual Recon: Web Recon (CommonHuman-Lab/nyxstrike, 156 stars), Hunt Auth Bypass (elementalsouls/Claude-BugHunter, 4.8k stars), Hunt Business Logic (majiayu000/claude-skill-registry, 666 stars) and Web3 Smart Contract Audit (awarexone/Agentic-Bug-Hunter, 5.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Visual Recon?

uphiago (a GitHub user) maintains it in uphiago/recon-skills, which has 1,294 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on September 1, 2026.

Source: uphiago/recon-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.