What problem does it solve? Red-team operators and bug-bounty hunters waste time reconstructing probe wordlists, secret regexes, and enumeration endpoints from scratch for every engagement. This Skill centralizes the concrete operational data needed for authorized external reconnaissance into one indexed arsenal. ## Core Features & Use Cases - Probe & Wordlist Arsenal: 28 Swagger/OpenAPI paths, 13 GraphQL paths with introspection body, 35 high-risk ports, cloud-bucket permutation generator (S3/GCS/Azure), and copy-paste curl one-liners for 15 always-on HTTP checks. - Secret & Identity Intelligence: 48-pattern secret regex catalog (AWS, GitHub, Stripe, Anthropic, OpenAI, npm, PyPI), 9 read-only secret validators, and concrete identity-fabric endpoints for Entra, Okta, ADFS, Google Workspace, and M365 deep enumeration. - Scoring & Triage Rubrics: 0-100 endpoint interest score, mobile app ownership confidence rubric, 27 attack-path hint templates, and an 80+ example severity decision matrix. - Use Case: During an authorized bug-bounty engagement against example.com, load the probes reference to enumerate subdomains and exposed .git/.env files, validate a leaked GitHub PAT read-only, then score each discovered endpoint and emit severity-tagged findings with evidence hashes. ## Quick Start Ask the AI to run an external recon pass on an authorized target domain using the offensive-osint probes, wordlists, and severity rubric.