#107 · Primary category: Cybersecurity & Decryption Tools
recon-skills
Recon & pentest skill pack. CORS, XSS, SQLi, SSRF, RCE, WordPress, MCP, cloud, subdomain takeover, and more. Field-tested. MIT. Full write-up at hiago.sh
Project last updated:08/24/26
GitHub Stars
1.2K
Forks
209
Contributors
3
License
MIT
Why we included this project
Security teams running external web assessments will find this a practical, field-tested reference rather than a pile of one-off PoCs. It bundles a large set of structured skill documents that cover the whole engagement: subdomain, DNS, port, and technology discovery; route, parameter, and API mapping; authentication and SSO testing; and validation of vulnerability classes like CORS, XSS, SQLi, SSRF, and RCE. Each skill records its prerequisites, procedure, common pitfalls, and verification criteria, so it works both as a manual playbook and as task context for an automation harness. The catalog is organized so you can start from broad recon entry points and pull in platform-specific skills (WordPress, cloud, Firebase, Supabase) only when discovery produces a relevant signal. It is a curated knowledge pack for authorized testing, not a turnkey scanner, so it rewards operators who already know their tooling and want a repeatable methodology.
Articles for this project
No articles for this project yet.
To suggest a topic or contribute an article, contact us.
Related projects in this category
reverse-skill
AI-powered skill router for reverse engineering, authorized penetration testing, and security research, with on-demand toolchain bootstrapping and self-evolving knowledge base.
gitleaks
Find secrets with Gitleaks 🔑
osquery
SQL powered operating system instrumentation, monitoring, and analytics.
NeoPass
Your Essential Exam Companion for the Iamneo Portal & NPTEL Exams Disguised as NeoExamShield bypass
anubis
Weighs the soul of incoming HTTP requests to stop AI crawlers