recon-security

Coordinate and execute authorized external penetration tests from reconnaissance to reporting using free, open-source tools and structured evidence management.

76|11|Updated May 18, 2026
One-click install
npx skills add https://github.com/superagent-ai/skills --skill recon-security
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: recon-security
Source: https://github.com/superagent-ai/skills/tree/main/skills/recon-security
Command: npx skills add https://github.com/superagent-ai/skills --skill recon-security

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This skill provides a model-guided framework to run authorized external penetration tests from recon to reporting, helping teams map attack surfaces without relying on paid APIs.

Core Features & Use Cases

  • End-to-end engagement lifecycle guidance: recon, normalization, active discovery, web/app checks, validation, and reporting.
  • Guardrails and scoping: enforce RoE, risk controls, and evidence management; safe for teams with limited tooling.
  • Open-source tooling emphasis: leverages free/open-source scanners and local workflows for reproducible results.

Quick Start

Define scope and RoE, then begin passive reconnaissance with open-source tools to seed targets and evidence structure.

Frequently Asked Questions about recon-security

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I run an authorized external penetration test using open-source tools?▼

To run an authorized external penetration test, define your scope and Rules of Engagement, then execute passive reconnaissance with open-source scanners to seed targets and structure evidence for reproducible results.

What is evidence management in a pentesting workflow?▼

Evidence management in a pentesting workflow is the structured collection and normalization of reconnaissance data across web and infrastructure targets to ensure safe, reproducible engagements.

Can I map attack surfaces without relying on paid APIs?▼

You can map attack surfaces without paid APIs by leveraging free, open-source scanners within a model-guided framework to coordinate active discovery and web application checks.

What are the guardrails for executing safe external penetration tests?▼

Guardrails for safe external penetration tests involve enforcing Rules of Engagement, applying risk controls, and maintaining structured evidence management to protect teams with limited tooling.

Does model-guided reconnaissance work for both web and infrastructure targets?▼

Model-guided reconnaissance works for both web and infrastructure targets by coordinating end-to-end active discovery, validation, and reporting workflows across the engagement lifecycle.