Agent skill

Recon JS Analysis

by zhaji2333 in zhaji2333/CkSKILLS

当开始新目标、攻击面不清晰、需要资产测绘/信息收集/前端JS分析/接口与敏感信息提取时调用。负责webpack拆解、source map还原、API端点与密钥提取、历史资产发现、高价值入口定位。命中场景:找不到接口、需要找密钥/隐藏功能/旧版本接口、JS加密与签名逻辑需要还原。

MITAuto-check passedSecurity

Install Recon JS Analysis

skills CLI
$ npx skills add zhaji2333/CkSKILLS --skill recon-js-analysis -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install zhaji2333/CkSKILLS recon-js-analysis --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/zhaji2333/CkSKILLS.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/recon-js-analysis .claude/skills/recon-js-analysis && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
recon-js-analysis
GitHub stars
115
Token cost
~1.1k tokens
SKILL.md length
199 words
Files
1
Skills in repo
15
Repo updated
First seen
Licence
MIT

At a glance

当开始新目标、攻击面不清晰、需要资产测绘/信息收集/前端JS分析/接口与敏感信息提取时调用。负责webpack拆解、source map还原、API端点与密钥提取、历史资产发现、高价值入口定位。命中场景:找不到接口、需要找密钥/隐藏功能/旧版本接口、JS加密与签名逻辑需要还原。

  • Security work in your project
  • SKILL.md covers 何时调用(触发条件), 一、资产测绘与信息收集, 二、信息收集要"脏"(历史与周边) and 三、JS 分析方法论(必须吃透再动手), plus 3 more sections
  • Calls python and apk

What it does

Recon JS Analysis is an agent skill from zhaji2333/CkSKILLS. 当开始新目标、攻击面不清晰、需要资产测绘/信息收集/前端JS分析/接口与敏感信息提取时调用。负责webpack拆解、source map还原、API端点与密钥提取、历史资产发现、高价值入口定位。命中场景:找不到接口、需要找密钥/隐藏功能/旧版本接口、JS加密与签名逻辑需要还原。

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security. It works with webpack. The repository describes itself as: 基于 Claude Code / Codex 的 SRC 漏洞挖掘 Agent 技能体系 —— 将顶尖安全研究员的方法论沉淀为可调度、可复用的 Skill 知识资产。 The licence is MIT.

When your agent uses it

  • Security work in your project

Example prompts

  • “/recon-js-analysis”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit 482fe78. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python
    • apk

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Recon JS Analysis loads about 1.1k tokens when it runs. Until then it costs about 39 tokens; SKILL.md has 199 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~39
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from zhaji2333/CkSKILLS at commit 482fe78, republished under its MIT licence (© zhaji2333). 199 words, ~1,055 tokens.

Download SKILL.mdSave it as .claude/skills/recon-js-analysis/SKILL.md (or your agent's skills folder).
name
recon-js-analysis
description
当开始新目标、攻击面不清晰、需要资产测绘/信息收集/前端JS分析/接口与敏感信息提取时调用。负责webpack拆解、source map还原、API端点与密钥提取、历史资产发现、高价值入口定位。命中场景:找不到接口、需要找密钥/隐藏功能/旧版本接口、JS加密与签名逻辑需要还原。

recon-js-analysis — 资产测绘与前端 JS 深度分析

何时调用(触发条件)

  • 开始测试新目标,攻击面不清晰
  • 需要提取 API 端点、参数结构、鉴权逻辑、隐藏功能
  • 需要还原 webpack chunk / source map / 混淆代码
  • 需要找硬编码密钥、AK/SK、内部域名、测试账号
  • 需要发现、历史资产、旧版本接口
  • 需要确定高价值入口点(用户中心/支付/后台/API)

一、资产测绘与信息收集

端口服务:nmap / masscan / 云资产API
目录扫描:dirsearch / ffuf / 403绕过
JS分析:LinkFinder / SecretFinder / API端点提取
APP逆向:jadx / frida / 抓包分析隐藏接口

二、信息收集要"脏"(历史与周边)

必须尝试的信息源:

  • Wayback Machine:翻旧版本页面/JS(可能有已删除的接口和功能)
  • GitHub/GitLab搜索:目标域名、内部接口、泄露的密钥/配置
  • Google Dork:site:target.com filetype:pdf/xls/doc/sql/log/bak
  • 证书透明度日志:发现隐藏的子域名
  • 招聘JD:推断技术栈(用了什么框架→对应什么已知漏洞)
  • JS中的注释/TODO:开发者留下的线索
  • robots.txt / sitemap.xml:暴露的隐藏路径
  • 前端source map:还原完整前端源码
  • APK/IPA反编译:提取硬编码的接口和密钥
  • 更新日志/Changelog:新功能=新攻击面

三、JS 分析方法论(必须吃透再动手)

原则:JS不吃透,不发包。

3.1 完整还原
  • webpack chunk拆解、source map还原(如有)
  • 自动化工具:Packer-InfoFinder(开源 webpack 资产提取工具,可自动发现 JS、拆解 chunk、提取接口与敏感信息)
bash
# 单目标扫描(自动发现JS、拆解chunk、提取接口和敏感信息)
python Packer-InfoFinder.py -u https://target.com --finder

# 批量扫描
python Packer-InfoFinder.py -l urls.txt --finder

# 指定JS文件分析(跳过HTML入口,直接分析JS)
python Packer-InfoFinder.py -j "https://target.com/app.js,https://target.com/chunk.js"

# 无头浏览器模式(捕获动态加载的JS)
python Packer-InfoFinder.py -u https://target.com --browser --finder

# 带代理扫描
python Packer-InfoFinder.py -u https://target.com --finder -p http://127.0.0.1:7890
  • 格式化/美化混淆代码,逐模块阅读
  • 优先定位:路由定义、API调用、请求拦截器、响应处理器
3.2 必须提取的信息
  • 所有API端点(包括注释掉的、条件判断里的、环境变量控制的)
  • 请求参数结构(必填/选填/隐藏参数/调试参数)
  • 鉴权机制(token生成逻辑、签名算法、加密方式、刷新机制)
  • 前端路由表(React Router / Vue Router / Angular Routes)
  • 角色/权限判断逻辑(哪些功能对哪些角色开放)
  • 硬编码的密钥、AK/SK、内部域名、测试账号
  • URL / IP / 域名清单(webpack/app.js/抓包/反编译中所有请求地址):API 网关、后台/管理端域名、CDN/OSS 存储桶、内网 IP、云服务端点、第三方回调地址——每一条都是可扩展攻击面,单独列出并进入资产测绘流程
  • appid / appkey / AppSecret / 推送密钥等应用凭证:单独列出,作为重点深挖对象(见 3.3)
  • Feature Flag / Debug开关 / 环境判断(dev/test/prod)
  • WebSocket端点和消息格式
  • 错误处理逻辑(哪些错误会泄露信息)
3.3 资产扩展与凭证上报(提取后必须做)

① URL/IP/域名 → 资产扩展(可扩展分析内容)

  • 将提取的每个 URL、IP、域名单独成行,标注来源(webpack 提取 / app.js / source map / APP 抓包 / APK 反编译),便于交接与复盘
  • 全部进入资产测绘流程:子域名枚举、端口扫描、目录扫描、指纹识别
  • APP 中抓取的 URL/IP/域名要提醒用户关注:很可能是 APP 后台接口或业务接口域名,鉴权往往弱于前端接口,是比前端接口更高价值的测试目标(联动 android-security-audit / miniprogram-security)

② appid/appkey 等凭证 → 上报并深入挖掘

  • 提取到 appid/appkey/AppSecret/AK/SK/推送密钥后,必须上报给用户并单独列出,作为重点深挖对象,不允许只放在接口清单里带过
  • 深挖方向:
    • 验证有效性:用 appid/appkey 直接调用对应后端接口/云服务 API——云厂商 AK/SK 可致云资产接管(联动 cloud-infra-supply-chain)
    • 定位归属:凭证书透明度日志、代码仓库搜索、目标域名对比,确认凭证对应的域名与服务
    • 越权面:appid/appkey 对应的管理接口、统计接口、推送接口是否可越权调用、是否缺少鉴权
    • 泄漏面:多渠道验证(历史版本 JS、Wayback、日志、错误信息、GitHub 泄露)
3.4 分析输出格式
[JS分析报告]
接口清单:(列出所有发现的API端点)
参数结构:(每个接口的完整参数)
鉴权逻辑:(签名/加密/token机制)
隐藏功能:(debug接口/未启用功能/旧版接口)
可测试点:(按优先级排序)
3.5 测试执行
  • 每个接口必须测试全部HTTP方法(GET/POST/PUT/DELETE/PATCH/OPTIONS)
  • 每个参数必须测试:正常值、空值、边界值、类型混淆、数组化、超长、特殊字符
  • 鉴权接口:有token测、无token测、过期token测、其他用户token测
  • 发现的隐藏参数/调试参数全部尝试

四、高价值入口点定位

  • 用户中心:注册/登录/找回密码/绑定手机/实名认证
  • 支付流程:下单→支付→回调→退款→提现
  • 文件功能:头像上传/附件上传/导入导出/报表下载
  • 管理后台:/admin /manager /console /backstage
  • API接口:/api/v1 /graphql /swagger /actuator

五、冷门但高价值的漏洞点(攻击面速查)

场景漏洞类型挖掘思路
客服/工单系统存储XSS→钓鱼客服提交工单内容含XSS,客服后台触发
邮件/消息通知邮件头注入/SMTP注入收件人、主题可控时注入换行符
二维码/短链生成SSRF/重定向URL参数可控,探测内网或钓鱼
地图/定位服务信息泄露泄露内部POI、员工位置
日志/监控接口未授权+敏感信息/actuator /metrics /debug
第三方登录OAuth劫持redirect_uri校验不严
分享/邀请功能越权/信息泄露分享链接可遍历、权限过大
数据导出注入/越权导出条件可控、无归属校验

六、输出与交接

完成本技能后,将提取的接口清单、参数结构、鉴权机制、隐藏功能整理为可测试清单,按类型分发给对应专项技能;同时按 hunt-clueboard 写入 hunts/<目标>/CLUEBOARD.md(Host/路径/钥/否定证据当轮落盘,不只放在对话里):

  • 零身份、路径不在当前前端、加密当鉴权、迁域/兄弟域漏路径 → unauth-path-key-hunt
  • 接口/鉴权问题 → api-protocol-security / auth-access-control
  • 参数拼接/注入点 → injection-vulns
  • 文件相关功能 → file-handling
  • URL可控功能 → ssrf-internal-network
  • 提取的 URL/IP/域名清单 → 资产测绘扩展(新子域/新端口/新后台),APP 来源的提醒用户关注后台接口域名
  • 提取的 appid/appkey/AK/SK 等凭证 → 上报用户并深入挖掘(验证有效性、打云资产/后端接口,联动 cloud-infra-supply-chain)

© zhaji2333, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/recon-js-analysis of zhaji2333/CkSKILLS.

Open the folder on GitHubat commit 482fe78

Compare with similar skills

Recon JS Analysis next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Recon JS Analysis compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Recon JS Analysis this skillzhaji2333/CkSKILLS115—~1.1kAutomated safety check: PassMIT
Client Request Signature Reversalawarexone/Agentic-Bug-Hunter5.3k—~4.7kAutomated safety check: PassMIT
Reversing Obfuscated Javascripttrilwu/secskills157—~2.3kAutomated safety check: PassMIT
Liveblog Devliveblog/liveblog119—~1.9kAutomated safety check: PassAGPL-3.0
Plugin Bundle Sizegrafana/skills282—~3.6kAutomated safety check: PassApache-2.0
Sentry CI Integrationjeremylongshore/tons-of-skills-marketplace2.8k—~4.3kAutomated safety check: PassMIT

Similar skills

  • Client Request Signature Reversal

    awarexone/Agentic-Bug-Hunter

    Recovers a client-side request signature or anti-bot token just far enough to replay blocked requests in bug bounty testing, starting from a captured packet.

    5.3k GitHub stars~4.7k tokensUpdated yesterday
    SecurityAuto-check passed
  • Reverse engineer minified, bundled, and obfuscated browser/Node JavaScript — unpacking webpack chunks, recovering source from sourcemaps, undoing obfuscator.io string-array and control-flow…

    157 GitHub stars~2.3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Liveblog Dev

    liveblog/liveblog

    Run a local Liveblog development environment. An agent skill from liveblog/liveblog.

    119 GitHub stars~1.9k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Plugin Bundle Size

    grafana/skills

    Official

    Optimise Grafana app plugin bundle size using React.lazy, Suspense, and webpack code splitting.

    282 GitHub stars~3.6k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Sentry CI Integration

    jeremylongshore/tons-of-skills-marketplace

    Integrate Sentry into CI/CD pipelines for automated release creation, source map uploads, and deploy notifications.

    2.8k GitHub stars~4.3k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Tailing Build Output

    spencerpauly/awesome-cursor-skills

    Monitor a build process (webpack, turbo, docker) for warnings and errors as they stream.

    844 GitHub stars~524 tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed

More from zhaji2333/CkSKILLS

All 15 skills in this repo
  • Apk Reversing

    zhaji2333/CkSKILLS

    当需要获取目标 APK、识别加固壳类型、脱壳还原 dex、反编译得到 Java/so/H5 全量源码产物,或 android-security-audit 需要可直接开挖的输入时调用。负责 APK → 全量可审计产物(壳识别 → 脱壳 → JADX 反编译 + apktool 资源 + so 提取 + H5/assets 提取)→ 标准目录交付。命中场景:JADX 打开是…

    115 GitHub stars~1.7k tokensUpdated 26 days ago
    Auto-check passed
  • Asc Fast Hunt

    zhaji2333/CkSKILLS

    当需要在不对 APK 全量反编译的前提下秒级定位硬编码密钥/签名函数/隐藏接口/调试后门,或 APK 过大(100MB)JADX 全量反编译过慢、内存吃紧,或脱壳产物(裸 dex)需要快速检索,或只想先读一下 Manifest 组件面/权限清单时调用。负责基于 Droid ASC 的零预处理快速定位(findrefs 全局交叉引用搜索 + getclass 按需反编译 + Manifest…

    115 GitHub stars~3.3k tokensUpdated 26 days ago
    Auto-check passed
  • Business Logic Race

    zhaji2333/CkSKILLS

    当目标存在支付/下单/退款/提现/转账/优惠券/积分/红包/会员/订阅/审批/库存/抽奖等业务功能,或发现状态可跳变、金额参数可控、并发可重放时调用。负责业务状态机建模、金额篡改、订单状态跳变、竞态条件与重放攻击深度挖掘。

    115 GitHub stars~466 tokensUpdated 26 days ago
    Auto-check passed
  • AI LLM Agent Security

    zhaji2333/CkSKILLS

    当目标为 LLM 应用/Chatbot/智能客服/AI 助手/Copilot/Agent/RAG 知识库/多模态模型,或发现用户输入进入大模型提示、工具调用、知识库检索、对话记忆、文件解析,或需要测试提示词注入/越狱逃逸/System Prompt 泄露/训练数据与敏感信息泄露/RAG 检索污染/Agent 记忆污染/工具滥用与命令执行/SSRF/沙箱逃逸时调用。负责 OWASP LLM…

    115 GitHub stars~4.7k tokensUpdated 26 days ago
    Auto-check: warnings
  • Hunt Clueboard

    zhaji2333/CkSKILLS

    当开始挖新目标、换会话/压缩后续挖、用户说线索板/写板/读板/建板,或信息收集、反编译、JS/接口线索需要跨轮保留时调用。负责为当前系统维护一份 Markdown 线索板(读→挖→写回),不负责拆 webpack、打越权或成稿。模板见同目录 CLUEBOARD.template.md。

    115 GitHub stars~606 tokensUpdated 26 days ago
    Auto-check passed
  • Cloud Infra Supply Chain

    zhaji2333/CkSKILLS

    当目标涉及云资产(对象存储/云元数据/Serverless)、容器/K8s、运维面板(宝塔/Grafana/Zabbix/Jenkins/GitLab/Nacos等)、消息队列/缓存中间件、CI/CD流水线、第三方回调集成、依赖组件CVE、信息泄露配置时调用。负责未授权访问、弱口令、云配置错误、供应链漏洞与敏感信息挖掘。

    115 GitHub stars~688 tokensUpdated 26 days ago
    Auto-check: warnings

Works with

Categories

Questions about Recon JS Analysis

What does Recon JS Analysis do?

当开始新目标、攻击面不清晰、需要资产测绘/信息收集/前端JS分析/接口与敏感信息提取时调用。负责webpack拆解、source map还原、API端点与密钥提取、历史资产发现、高价值入口定位。命中场景:找不到接口、需要找密钥/隐藏功能/旧版本接口、JS加密与签名逻辑需要还原。. Recon JS Analysis is an agent skill from zhaji2333/CkSKILLS.

When should I use Recon JS Analysis?

Recon JS Analysis fits situations like: security work in your project.

How do I install Recon JS Analysis in Claude Code?

Run `npx skills add zhaji2333/CkSKILLS --skill recon-js-analysis -a claude-code`. Or copy the skill folder (.agents/skills/recon-js-analysis in zhaji2333/CkSKILLS) into .claude/skills/recon-js-analysis in your project. Claude Code loads it when a task matches its description.

How do I install Recon JS Analysis in Codex?

Run `npx skills add zhaji2333/CkSKILLS --skill recon-js-analysis -a codex`. Or copy the skill folder (.agents/skills/recon-js-analysis in zhaji2333/CkSKILLS) into .agents/skills/recon-js-analysis in your project. Codex loads it when a task matches its description.

Can I use Recon JS Analysis in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add zhaji2333/CkSKILLS --skill recon-js-analysis -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/recon-js-analysis, .gemini/skills/recon-js-analysis, .github/skills/recon-js-analysis and .opencode/skills/recon-js-analysis in your project.

What does Recon JS Analysis need to run?

Going by SKILL.md and its folder, Recon JS Analysis needs the command-line tools its instructions call (python and apk). Our summary lists: Python 3.

Does Recon JS Analysis access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Recon JS Analysis safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Recon JS Analysis use?

Recon JS Analysis is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Recon JS Analysis use?

About 1.1k tokens (SKILL.md is roughly 4.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Recon JS Analysis?

Skills that share tags, products or a category with Recon JS Analysis: Client Request Signature Reversal (awarexone/Agentic-Bug-Hunter, 5.3k stars), Reversing Obfuscated Javascript (trilwu/secskills, 157 stars), Liveblog Dev (liveblog/liveblog, 119 stars) and Plugin Bundle Size (grafana/skills, 282 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Recon JS Analysis?

zhaji2333 (a GitHub user) maintains it in zhaji2333/CkSKILLS, which has 115 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on September 15, 2026.

Source: zhaji2333/CkSKILLS on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.