What problem does it solve? Mapping a target's external attack surface normally requires active scanning that touches the target and appears in its logs. This Skill finds exposed hosts, open ports, services, and devices by querying third-party internet-scan platforms, keeping the reconnaissance fully passive. ## Core Features & Use Cases - Scan-platform querying: Covers Shodan and Censys query syntax, plus FOFA, ZoomEye, Netlas, and others, with a side-by-side query cookbook for translating intent across platforms. - Infrastructure pivots: Uses favicon hashes, TLS certificate subjects and serials, JARM fingerprints, and response-body strings to find sibling infrastructure and origin servers behind Cloudflare or other CDNs. - Banner interpretation and confidence grading: Distinguishes observed facts from self-reported banner claims, detects honeypots and stale records, and grades findings as confirmed, probable, or unconfirmed. - Use Case: During an authorized external attack-surface review of a company behind Cloudflare, search scan data for its TLS certificate on IPs outside the CDN's ASNs to locate the likely origin server, then report an exposed MySQL port found on the same netblock with scan dates and queries. ## Quick Start Ask the agent to find what example.com has exposed to the internet using passive scan data from Shodan and Censys.