passive-recon
Collect external context without touching the target aggressively.
Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.
Menu
Collect external context without touching the target aggressively.
Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.
Based on SOC occupation classification
Four-phase autonomous bug bounty orchestration. Phase 0 maps external assets with deterministic Python helpers, Phase 1 lets AI prioritize attack surfaces, Phase 2 gives AI autonomous attack control, and Phase 3 produces verifier-only reports.
Four-phase autonomous bug bounty workflow. Python handles deterministic collection and verifier support; AI owns prioritization, attack reasoning, and autonomous direction changes.
Report generation agent. Convert verifier-confirmed findings into a fixed evidence-based report without adding speculative impact.
Rank reconnaissance-derived attack surfaces and design evidence-driven tests without active exploitation.
Test ranked attack surfaces autonomously, preserve evidence, and turn new access into additional attack-chain hypotheses.
A compact routing skill for choosing vulnerability hypotheses; detailed payloads live in references, not here.
| name | passive-recon |
| description | Collect external context without touching the target aggressively. |
| metadata | {"tags":"passive-recon,dns,wayback,ct"} |
用被动来源建立目标画像,并找出值得后续主动验证的资产。