Self-hosted service
uphiago/recon-skills avatar
uphiago/recon-skills

recon-skills: A Structured Skill Pack for Authorized External Web Penetration Testing

Recon & pentest skill pack. CORS, XSS, SQLi, SSRF, RCE, WordPress, MCP, cloud, subdomain takeover, and more. Field-tested. MIT. Full write-up at hiago.sh

1,276 stars213 forksPythonMIT

At a glance

What is it?
recon-skills is a MIT-licensed collection of structured penetration testing skills for external web security assessments, covering subdomain discovery, authentication testing, vulnerability validation, and attack-path analysis, designed for authorized use only.
Who is it for?
recon-skills is for security professionals running authorized external assessments on web applications and APIs. The catalog is well organized, covers the standard external web attack surface, and documents each skill's prerequisites and pitfalls.
Can I use it commercially?
Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 29 days ago.
What is it written in?
Mainly Python, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 17, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What recon-skills is and who it is for

recon-skills is a collection of individual security assessment procedures, each packaged as a SKILL.md file within a structured directory. The collection is aimed at security professionals conducting authorized penetration tests and bug bounty assessments of external web applications, APIs, and internet-facing infrastructure. The README states directly that these skills are for authorized security testing only, and that testers should only run them against targets they own or have explicit written permission to test.

Each skill in the catalog owns a focused objective. The README describes what that means: prerequisites, the procedure to follow, pitfalls to watch for, verification criteria for confirming a finding, and related techniques. This structure makes the skills usable both as manual checklists and as task context for an automation system that can load SKILL.md files.

The catalog is not a single automated scanner. It is a library of documented procedures that a tester selects based on what the target surface reveals. This design assumes that the tester will evaluate which skills apply based on the reconnaissance they have already completed, rather than running all skills blindly.

Catalog structure: six directories and what each covers

The repository organizes skills into six top-level directories:

bash
recon-skills/
|-- auth/       Authentication and SSO testing
|-- chains/     Multi-step attack-path analysis
|-- infra/      Infrastructure-focused techniques
|-- meta/       Engagement planning and cross-skill workflows
|-- recon/      Discovery, enumeration, and focused validation
`-- redteam/    Vulnerability-class and platform playbooks

The recon/ directory covers discovery and enumeration: subdomain enumeration, port and service discovery, web path and technology enumeration, JavaScript secrets extraction, and similar surface-mapping work. These are typically the first skills used in an assessment.

The auth/ directory covers authentication testing across protocols including OAuth, SAML, MFA, and standard session management. The redteam/ directory holds vulnerability-class playbooks covering CORS, XSS, SQLi, SSRF, RCE, subdomain takeover, cloud pivots, and WordPress-specific techniques. The chains/ directory covers multi-step attack paths where multiple findings combine into a higher-severity result. The meta/ directory holds engagement planning workflows, and the infra/ directory covers infrastructure-level techniques including container and cloud identity pivots.

Getting started: clone, locate, and set an output directory

Using recon-skills starts with cloning the repository and locating the skills relevant to the target surface:

bash
git clone https://github.com/uphiago/recon-skills.git
cd recon-skills

find . -name SKILL.md -print | sort
rg -n "SSRF|OAuth|GraphQL|Kubernetes" --glob 'SKILL.md'

The first command lists all SKILL.md files in sorted order, providing a full catalog view. The second uses `rg` (ripgrep) to search for a specific technique or technology across all skill files, which is more efficient than reading each file when looking for a narrow topic.

Before running any examples from the skills, set the output directory variable:

bash
export OUTPUT_DIR="${OUTPUT_DIR:-./output}"
mkdir -p "$OUTPUT_DIR"

The README notes that commands assume standard Linux tooling unless a skill states otherwise. Tool availability, scope restrictions, network policy, credentials, and isolation are the operator's responsibility, not something the skill files manage automatically.

For a broad external web assessment, the README recommends starting with `redteam/web2-recon`, `recon/subdomain-enumeration`, `recon/web-enumeration`, and `redteam/bb-methodology` before adding vulnerability-specific or platform-specific skills.

High-signal entry points for different assessment types

The README documents a table of high-signal entry points that map skill paths to their primary purpose. `meta/recon-playbook` provides an end-to-end recon workflow with escalation gates, making it the right starting point for anyone unfamiliar with how the skills connect. `redteam/bb-methodology` covers bug bounty methodology and prioritization for timed assessments.

For specific vulnerability classes, the hunt skills cover individual attack types. The recon/js-secrets-extraction skill handles client-side bundle and secrets analysis, which is a common source of findings in modern web applications. The chains/cross-attack-chains skill is designed for evidence-based attack-path construction once individual findings have been validated.

The redteam/evidence-hygiene and redteam/report-writing skills cover the output side of an assessment: how to capture reproducible evidence with appropriate redaction, and how to write deliverables for client or bug bounty submission. These are part of the catalog because an assessment without a usable report is incomplete from a professional standpoint.

Quality baseline and the catalog validator

The quality baseline for skills in the catalog lives in STYLE.md, and the contributor guidance lives in AGENTS.md. The README notes that older skills are being migrated incrementally to the complete quality baseline, which means the catalog is in a transitional state: some skills have the full prerequisite and verification structure including explicit pitfalls and verification criteria, while others do not yet meet that standard.

A catalog validator script is included to check structural correctness before using a skill or reviewing a contribution:

bash
python3 scripts/validate_skills.py

Structural errors fail the command with a non-zero exit code. Style debt from skills that have not yet been migrated to the full quality baseline is reported separately as warnings, not errors. This separation lets contributors improve skills incrementally without breaking the catalog validation gate for new contributions. The distinction matters in practice: a structurally valid skill can still have thin documentation if it predates the current quality standard.

The operating principles of the project live in SOUL.md, a file that the README references alongside STYLE.md and AGENTS.md as the three governance documents for the catalog. Reading SOUL.md before submitting a new skill gives contributors the intended philosophy behind the project's approach to responsible disclosure and methodology documentation.

Limitations and comparison with automated scanners

recon-skills is not an automated scanner. It is documentation for a human tester or an AI agent that can load SKILL.md files as context. Running a skill requires reading it, understanding the prerequisites, and executing the commands manually or delegating them to an automation layer that understands the skill format. The skills assume the operator can interpret results: a subdomain enumeration skill lists what to run, but deciding which discovered subdomains are in scope and which findings are worth pursuing requires judgment that the documentation cannot provide.

Coverage is focused on external web security. The catalog does not address internal network penetration testing, physical security, social engineering, or mobile application security beyond API surface testing. Cloud pivots are covered in the infra/ directory, but a full cloud security assessment would require skills beyond what this catalog provides. The README lists the catalog as focused on external web, APIs, authentication, and infrastructure pivots, which is accurate as a description of its scope.

Burp Suite Professional, a commercial web application security platform, provides automated scanning, an intercepting proxy for manual testing, and a large library of built-in active scan checks. The difference from recon-skills is that Burp Suite is an interactive tool with its own GUI and automated scanning engine, while recon-skills is a documented procedure library that works with standard command-line tools. A security professional would typically use Burp Suite for intercepted request testing and recon-skills for structured methodology, documentation of what to check, and engagement planning.

The project is MIT licensed and the last push was on 2026-09-01. There are no GitHub releases; skill updates accumulate through direct commits to the repository files.

Editorial conclusion

recon-skills is for security professionals running authorized external assessments on web applications and APIs. The catalog is well organized, covers the standard external web attack surface, and documents each skill's prerequisites and pitfalls. It is not for passive reconnaissance only: the skills include active validation of vulnerabilities and attack-path construction, so scope and authorization must be confirmed before any execution. The last push was on 2026-09-01. The catalog validator at scripts/validate_skills.py gives a quick structural check before using a skill in an engagement. Teams doing internal network penetration tests, mobile application assessments, or physical security engagements will find limited coverage here, since recon-skills is focused on external web and API surfaces.

Frequently asked questions

Is recon-skills legal to use?

The README states that these skills are for authorized security testing only and that users should only test targets they own or have explicit written permission to test. Using these skills against targets without authorization would be illegal in most jurisdictions.

How do I find a specific technique in recon-skills?

Clone the repository and use ripgrep to search for the technique name or vulnerability class across all SKILL.md files: rg -n "technique name" --glob 'SKILL.md'. Alternatively, run find . -name SKILL.md -print | sort to list all available skills and navigate to the relevant directory.

What tools does recon-skills require?

The README says commands assume standard Linux tooling unless a skill states otherwise. Tool availability is the operator's responsibility. The meta/recon-playbook skill covers the engagement workflow and lists prerequisites, and individual skills document their specific tool requirements in their prerequisites section.

Official sources

  1. Issues
  2. License: MIT
  3. Project website
  4. README
  5. uphiago/recon-skills on GitHub
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/uphiago-recon-skills.svg)](https://hysenlabs.com/projects/uphiago-recon-skills)