recon-and-osint

Installation
SKILL.md

Recon & OSINT (RECON phase — the front of the lifecycle)

Overview

Find what's actually exposed before deciding what to test. Threat modeling assumes a surface; recon discovers it. Most breaches start at an asset the defender forgot they had.

Core principle: You can't protect what you don't know exists. Enumerate everything first.

⚠️ Authorization

Only enumerate assets you own or are explicitly authorized to test. Passive OSINT on your own org is always safe; active scanning/brute-forcing requires the asset to be in scope.

Installs
35
GitHub Stars
45
First Seen
Jun 8, 2026
recon-and-osint — mn-youssef/security-skills