
Recon For Sec
- 2.4k installs
- 1.5k repo stars
- Updated June 16, 2026
- yaklang/hack-skills
recon-for-sec is an agent skill that >-.
About
This is the starting router for new targets and unknown attack surfaces You just received a new target and do not yet know what to test first You need to begin with asset discovery tech fingerprinting endpoint inventory and test route planning You want to build follow up testing on structured methodology instead of random payload enumeration Recon and Methodology recon and methodology SKILL md Insecure Source Code Management insecure source code management SKILL md git svn hg exposure detection Dependency Confusion dependency confusion SKILL md Supply chain reconnaissance for internal package names 1 First confirm in scope assets and target type 2 Then perform asset discovery port service identification technology fingerprinting and endpoint collection 3 Route based on collected findings to api sec api sec SKILL md auth sec auth sec SKILL md injection checking injection checking SKILL md or business logic vuln business logic vuln SKILL md
- Entry P1 category router for reconnaissance and methodology. Use when mapping
- scope, discovering assets, fingerprinting technology, building endpoint
- inventory, and choosing the first high-value security testing path.
- Follow recon-for-sec SKILL.md steps and documented constraints.
- Follow recon-for-sec SKILL.md steps and documented constraints.
Recon For Sec by the numbers
- 2,361 all-time installs (skills.sh)
- +129 installs in the week ending Aug 5, 2026 (Skillselion tracking)
- Ranked #412 of 16,546 AI & Agent Building skills by installs in the Skillselion catalog
- Security screen: LOW risk (skills.sh audit)
- Data as of Aug 5, 2026 (Skillselion catalog sync)
recon-for-sec capabilities & compatibility
- Capabilities
- entry p1 category router for reconnaissance and · scope, discovering assets, fingerprinting techno · inventory, and choosing the first high value sec · follow recon for sec skill.md steps and document
- Use cases
- orchestration
What recon-for-sec says it does
Entry P1 category router for reconnaissance and methodology. Use when mapping
scope, discovering assets, fingerprinting technology, building endpoint
inventory, and choosing the first high-value security testing path.
npx skills add https://github.com/yaklang/hack-skills --skill recon-for-secAdd your badge
Show developers this skill is listed on Skillselion. Paste this into your README.
| Installs | 2.4k |
|---|---|
| repo stars | ★ 1.5k |
| Security audit | 3 / 3 scanners passed |
| Last updated | June 16, 2026 |
| Repository | yaklang/hack-skills ↗ |
When should an agent use recon-for-sec and what problem does it solve?
>-
Who is it for?
Developers invoking recon-for-sec as documented in the skill source.
Skip if: Skip when requirements fall outside recon-for-sec documented scope.
When should I use this skill?
>-
What you get
Outputs aligned with the recon-for-sec SKILL.md workflow and stated deliverables.
- Asset map
- Technology fingerprint
- Endpoint inventory
Files
Recon and Methodology Router
This is the starting router for new targets and unknown attack surfaces.
When to Use
- You just received a new target and do not yet know what to test first
- You need to begin with asset discovery, tech fingerprinting, endpoint inventory, and test-route planning
- You want to build follow-up testing on structured methodology instead of random payload enumeration
Skill Map
- Recon and Methodology
- Insecure Source Code Management — .git/.svn/.hg exposure detection
- Dependency Confusion — Supply chain reconnaissance for internal package names
Recommended Flow
1. First confirm in-scope assets and target type 2. Then perform asset discovery, port/service identification, technology fingerprinting, and endpoint collection 3. Route based on collected findings to api-sec, auth-sec, injection-checking, or business-logic-vuln
Related skills
How it compares
Start here before specialized yaklang exploitation skills when the target surface is still unknown.
FAQ
What is recon-for-sec?
>-
When should I use recon-for-sec?
>-
Is recon-for-sec safe to install?
Review the Security Audits panel on this page before production use.