跳到正文

uphiago

recon-skills

Recon & pentest skill pack. CORS, XSS, SQLi, SSRF, RCE, WordPress, MCP, cloud, subdomain takeover, and more. Field-tested. MIT. Full write-up at hiago.sh

README 已保存到本站,可直接阅读

Documentation snapshot

README 快照

这篇是英文原文

下面正文是项目自己的英文 README。想读全文就用浏览器自带的整页翻译: Chrome / Edge 点地址栏右侧的翻译图标,或用右键菜单里的「翻译成中文」; 手机浏览器一般在菜单里。

本页保存的是公开项目资料快照,阅读过程不需要连接 GitHub。

Recon Skills

A curated pack of security skills for external reconnaissance, web applications, APIs, authentication, vulnerability validation, attack-path analysis, and reporting.

These skills are for authorized security testing only. Only test targets you own or have explicit written permission to test.

Blog & research: hiago.sh - Pentest Playbook, field notes, and tooling.

What Is Included

The catalog is primarily focused on external web security:

  • subdomain, DNS, port, HTTP, and technology discovery;
  • route, parameter, JavaScript, source-map, and API mapping;
  • authentication, authorization, session, OAuth, SAML, and MFA testing;
  • web vulnerability and framework-specific validation;
  • cloud, identity, container, and exposed-infrastructure pivots;
  • evidence review, attack-path analysis, and reporting.

Each skill owns a focused objective and documents the prerequisites, procedure, pitfalls, verification criteria, and related techniques needed for that objective. Older skills are being migrated incrementally to the complete quality baseline.

Catalog

recon-skills/
|-- auth/       Authentication and SSO testing
|-- chains/     Multi-step attack-path analysis
|-- infra/      Infrastructure-focused techniques
|-- meta/       Engagement planning and cross-skill workflows
|-- recon/      Discovery, enumeration, and focused validation
`-- redteam/    Vulnerability-class and platform playbooks

Using the Pack

Clone the repository and locate the skills that match the observed surface:

git clone https://github.com/uphiago/recon-skills.git
cd recon-skills

find . -name SKILL.md -print | sort
rg -n "SSRF|OAuth|GraphQL|Kubernetes" --glob 'SKILL.md'

For a broad external web assessment, useful entry points are redteam/web2-recon, recon/subdomain-enumeration, recon/web-enumeration, and redteam/bb-methodology. Add vulnerability or platform skills only when discovery produces a relevant signal.

Set a writable output location before running examples:

export OUTPUT_DIR="${OUTPUT_DIR:-./output}"
mkdir -p "$OUTPUT_DIR"

Commands assume standard Linux tooling unless a skill states otherwise. Tool availability, scope, network policy, concurrency, credentials, and isolation remain the operator’s responsibility.

High-Signal Entry Points

SkillPurpose
meta/recon-playbookEnd-to-end recon workflow and escalation gates
redteam/bb-methodologyBug bounty methodology and prioritization
redteam/web2-reconBroad web attack-surface discovery
redteam/offensive-osintExternal intelligence and asset pivots
recon/subdomain-enumerationPassive and active subdomain discovery
recon/port-service-discoveryPort and service classification
recon/web-enumerationWeb paths, files, and technology enumeration
recon/js-secrets-extractionClient-side bundle and secret analysis
chains/cross-attack-chainsEvidence-based attack-path construction
redteam/triage-validationFinding validation before reporting
redteam/evidence-hygieneReproducible and redacted evidence capture
redteam/report-writingClient and bug bounty reporting

The hunt-* skills cover individual vulnerability classes and platform surfaces. Skills can be followed manually or loaded as task context by an automation system. Commands use standard tools and write persistent artifacts beneath ${OUTPUT_DIR:-./output} unless a skill documents another input.

Quality and Safety

The quality baseline lives in STYLE.md. Contributor guidance lives in AGENTS.md. The operating principles live in SOUL.md.

Run the catalog validator before reviewing a change:

python3 scripts/validate_skills.py

Structural errors fail the command. Existing style debt is reported separately as warnings so it can be improved incrementally.

License

MIT. See LICENSE.

Official distribution

获取与安装

暂未发现可确认的官方软件包地址

当前 README 快照没有出现 npm、PyPI、Crates.io、pub.dev 等官方包页链接。本站不会根据仓库名称猜测下载地址。

本站不托管项目文件;需要安装时,请以项目维护者发布的官方文档为准。

使用前核验

本站保存公开资料用于阅读,不代表安全审计或功能背书。安装前请核对许可证、依赖来源和发布签名,不要直接运行来源不明的二进制文件或高权限脚本。