uphiago/recon-skills

Recon & pentest skill pack. CORS, XSS, SQLi, SSRF, RCE, WordPress, MCP, cloud, subdomain takeover, and more. Field-tested. MIT. Full write-up at hiago.sh

About the project

Recon Skills is a pack of security-testing skills covering reconnaissance, web applications, APIs, authentication, vulnerability validation, cloud infrastructure, and reporting. Security professionals use it for authorized assessments of systems they own or have written permission to test. The catalogue entries are individual skills from the pack.

This repository also configures its own agents. See what recon-skills tells them →

1.3kStars on the repository
147Mods indexed here, across every type
10d agoLast push, which is what freshness is scored on
MITLicence, which decides whether bodies are shown

hunt-xxe

121

uphiago/recon-skills

Skill Claude CodeCodex

Hunting skill for xxe vulnerabilities. Built from 10 public bug bounty reports including SVG-upload XXE, Office-doc (PPTX/DOCX) XXE, SOAP XXE, SAML AssertionConsumer XXE, blind OOB XXE via DTD callback, parameter-entity XXE, XXE-to-LFI, XXE-to-SSRF, and XXE-to-RCE chains (Adobe Commerce CosmicSting CVE-2024-34102).…

not rated 1.3k +26 10d ago C SkillSpector: warn 127 tokens original MIT

llm-prompt-injection

122

uphiago/recon-skills

Skill Claude CodeCodex

Use when testing an authorized LLM application for prompt injection, system-prompt exposure, unsafe tool use, or RAG data-boundary failures.

not rated 1.3k +26 10d ago C SkillSpector: warn 36 tokens original MIT

m365-entra-attack

123

uphiago/recon-skills

Skill Claude CodeCodex

Microsoft 365 / Entra ID red-team attack chain — current 2026 reality. AADSTS code reference, user enumeration vectors (with hardening status), Smart Lockout math, Conditional Access bypass options, ROPC + SAML SSO browser flow, Burp/Playwright templates. Built from authorized red-team work where ROPC spray surfaced…

not rated 1.3k +26 10d ago A SkillSpector: pass 128 tokens original MIT

meme-coin-audit

124

uphiago/recon-skills

Skill Claude CodeCodex needs its repo

Meme coin and token security audit — rug pull detection (honeypot, hidden mint, fee manipulation, LP lock bypass), Solana SPL token analysis (freeze authority, mint authority, metadata mutability), Token-2022 extension risks (transfer hooks, permanent delegate), DEX liquidity pool attacks (sandwich amplification, LP…

not rated 1.3k +26 10d ago A SkillSpector: pass 123 tokens original MIT

uphiago/recon-skills

Skill Claude CodeCodex

Methodology for detecting client SOC patches, attacker activity, and security-state changes that occur DURING a red-team engagement — and converting those observations into deliverable findings. Built from authorized red-team work where the client patched a confirmed SQLi within 30 minutes of detection AND an external…

not rated 1.3k +26 10d ago A SkillSpector: pass 120 tokens original MIT

offensive-osint

126

uphiago/recon-skills

Skill Claude CodeCodex

Operational arsenal for authorized external red-team and bug-bounty recon. Concrete probes, wordlists, regexes, dorks, curl one-liners for: subdomain enum, GraphQL/Swagger/REST discovery, identity fabric (Entra/Okta/ADFS/Google/SAML/M365 deep — Teams/SharePoint/OneDrive), cloud bucket enum (S3/GCS/Azure), CDN/WAF…

not rated 1.3k +26 10d ago C SkillSpector: warn 179 tokens original MIT

okta-attack

127

uphiago/recon-skills

Skill Claude CodeCodex

Okta-as-IdP red-team attack chain — tenant discovery, user enumeration (multiple vectors), authentication flow analysis (factors enumeration, push-notification fatigue, SMS bypass), password spray with lockout discipline, Okta-specific phishing primitives (kits, FastPass abuse, OIDC redirecturi tampering), MFA…

not rated 1.3k +26 10d ago B SkillSpector: warn 149 tokens original MIT

ops-proxyns

128

uphiago/recon-skills

Skill Claude CodeCodex

Kernel-level proxy protection via proxy-ns — forces ALL traffic (TCP/UDP/DNS) through Tor using Linux network namespaces. Unlike proxychains, this works with Go/Rust/static binaries, prevents DNS leaks, and is impossible for applications to bypass. Includes Tor circuit rotation, IPv6 leak prevention, stealth headers…

not rated 1.3k +26 10d ago D 117 tokens original MIT

osint-methodology

129

uphiago/recon-skills

Skill Claude CodeCodex

Comprehensive OSINT methodology for external red-team operations and authorized attack-surface assessments. Covers the 5-stage recon pipeline (seed discovery, asset expansion, enrichment, exposure analysis, reporting), asset-graph discipline with 29 asset types, severity rubric (CRITICAL/HIGH/MEDIUM/LOW/INFO)…

not rated 1.3k +26 10d ago B SkillSpector: warn 258 tokens original MIT

uphiago/recon-skills

Skill Claude CodeCodex

End-to-end password spray playbook. User enumeration, lockout detection, password pattern generation, spray execution across all protocols, error code differentials, and engagement discipline. Unifies M365/Entra, Okta, Exchange, Kerberos, SharePoint, XMLRPC, OIDC, and AD SMB/WinRM spraying into one methodology.

not rated 1.3k +26 10d ago A SkillSpector: warn 76 tokens original MIT

uphiago/recon-skills

Skill Claude CodeCodex

Multi-sector batch domain expansion — identify untested/under-tested sectors, generate candidate company domains (national chains, franchises, regionals), filter against existing test coverage, probe alive domains, and run the full testing pipeline across 20+ new targets in a single session. Complements per-sector…

not rated 1.3k +26 10d ago A SkillSpector: warn 77 tokens original MIT

recon-sector

132

uphiago/recon-skills

Skill Claude CodeCodex needs its repo

Parameterized sector recon using sector database.

not rated 1.3k +26 10d ago A SkillSpector: warn 11 tokens original MIT

redteam-mindset

133

uphiago/recon-skills

Skill Claude CodeCodex

Red-team operator discipline — the mindset corrections that separate offensive testing from defensive WAPT. Built from authorized red-team work where conservative defaults caused multiple findings to be missed and one to be incorrectly retracted. Use at the START of any red-team engagement and again whenever feeling…

not rated 1.3k +26 10d ago A SkillSpector: pass 94 tokens original MIT

uphiago/recon-skills

Skill Claude CodeCodex

Client-facing red-team deliverable format — codifies the Subject / Observations / Description / Impact / Recommendation / PoC structure used for external red-team engagements (not bug-bounty platform reports). Different audience, different tone, different cadence. Built from an authorized engagement deliverable where…

not rated 1.3k +26 10d ago A SkillSpector: pass 139 tokens original MIT

report-writing

135

uphiago/recon-skills

Skill Claude CodeCodex

Bug bounty report writing for H1/Bugcrowd/Intigriti/Immunefi — report templates, human tone guidelines, impact-first writing, CVSS 3.1 scoring, title formula, impact statement formula, severity decision guide, downgrade counters, pre-submit checklist. Use after validating a finding and before submitting. Never use…

not rated 1.3k +26 10d ago A SkillSpector: pass 82 tokens original MIT

security-arsenal

136

uphiago/recon-skills

Skill Claude CodeCodex needs its repo

Security payloads, bypass tables, wordlists, gf pattern names, always-rejected bug list, and conditionally-valid-with-chain table. Use when you need specific payloads for XSS/SSRF/SQLi/XXE/NoSQLi/command injection/SSTI/IDOR/path-traversal/HTTP smuggling/WebSocket/MFA bypass, bypass techniques, or to check if a finding…

not rated 1.3k +26 10d ago B SkillSpector: warn 103 tokens original MIT

uphiago/recon-skills

Skill Claude CodeCodex

External recon for software supply-chain attack surface — package-namespace squatting candidates, dependency-confusion vulnerabilities, GitHub Actions injection openings, container image registry exposure, SBOM mining, internal-package-name leakage, and CI/CD configuration exposure. Reconnaissance and identification…

not rated 1.3k +26 10d ago C SkillSpector: warn 141 tokens original MIT

triage-validation

138

uphiago/recon-skills

Skill Claude CodeCodex

Finding validation before writing any report — 7-Question Gate (all 7 questions), 4 pre-submission gates, always-rejected list, conditionally valid with chain table, CVSS 3.1 quick reference, severity decision guide, report title formula, 60-second pre-submit checklist. Use BEFORE writing any report. One wrong answer…

not rated 1.3k +26 10d ago A SkillSpector: pass 87 tokens original MIT

web2-recon

139

uphiago/recon-skills

Skill Claude CodeCodex

Web2 recon pipeline — subdomain enumeration (subfinder, Chaos API, assetfinder), live host discovery (dnsx, httpx), URL crawling (katana, waybackurls, gau), directory fuzzing (ffuf), JS analysis (LinkFinder, SecretFinder), continuous monitoring (new subdomain alerts, JS change detection, GitHub commit watch). Use when…

not rated 1.3k +26 10d ago C SkillSpector: warn 103 tokens original MIT

web3-audit

140

uphiago/recon-skills

Skill Claude CodeCodex needs its repo

Smart contract security audit — 10 DeFi bug classes (accounting desync, access control, incomplete path, off-by-one, oracle, ERC4626, reentrancy, flash loan, signature replay, proxy), pre-dive kill signals (TVL < $500K etc), Foundry PoC template, grep patterns for each class, and real Immunefi paid examples. Use for…

not rated 1.3k +26 10d ago A SkillSpector: pass 103 tokens original MIT

uphiago/recon-skills

Skill Claude CodeCodex

Use when verified WordPress CORS, XML-RPC, role, upload, and execution behaviors may form one authorized attack path.

not rated 1.3k +26 10d ago A SkillSpector: warn 36 tokens original MIT

wp-plugin-automation

142

uphiago/recon-skills

Skill Claude CodeCodex

Scripts and workflows to batch-test popular WordPress plugin CVEs across hundreds of domains. Covers automated plugin detection, version extraction from readme.txt, CVE matching against a curated matrix of high-impact plugin vulnerabilities (ElementsKit, Revslider, WPDM, Gravity Forms, Contact Form 7, Jetpack, WP File…

not rated 1.3k +26 10d ago C SkillSpector: warn 112 tokens original MIT

wp-plugin-cve-hunt

143

uphiago/recon-skills

Skill Claude CodeCodex

Systematic approach to finding and testing CVEs for identified WordPress plugins. Covers plugin discovery, version extraction from multiple sources (readme.txt, assets, inline JS), CVE database cross-referencing with WPScan/Patchstack/NVD/NVD API, version-based vulnerability matching, exploitation PoC generation, and…

not rated 1.3k +26 10d ago D 160 tokens original MIT

wstg-web-pentest

144

uphiago/recon-skills

Skill Claude CodeCodex needs its repo

Full WSTG-aligned web application pentest — 12-phase methodology from information gathering through reporting, with concrete commands, expected outputs, pitfalls, and verification per phase.

not rated 1.3k +26 10d ago A SkillSpector: warn 42 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: