recon-and-osint
Installation
SKILL.md
Recon & OSINT (RECON phase — the front of the lifecycle)
Overview
Find what's actually exposed before deciding what to test. Threat modeling assumes a surface; recon discovers it. Most breaches start at an asset the defender forgot they had.
Core principle: You can't protect what you don't know exists. Enumerate everything first.
⚠️ Authorization
Only enumerate assets you own or are explicitly authorized to test. Passive OSINT on your own org is always safe; active scanning/brute-forcing requires the asset to be in scope.