recon-bakeries
Installation
SKILL.md
RECON-BAKERIES — Sector-Specific Recon for Bakeries & Pastry Shop Sites
When to Use
Use when the target scope includes bakeries, pastry shops, cake shops, donut shops, or dessert company domains. These small businesses typically run e-commerce sites for cake/pastry ordering with custom order forms for special occasions (weddings, birthdays), catering menus, and store locators. Common vulnerabilities: e-commerce API exposure (WooCommerce/Shopify), custom order form injection, coupon code enumeration, exposed delivery addresses in order tracking, and CSV export leakage of customer orders.
Quick Reference
- Common CMS: WordPress/WooCommerce (dominant), Shopify, Squarespace
- Common platforms: WooCommerce, Shopify, EatStreet, Toast POS, Slice, Upserve
- Key endpoints:
/shop,/order,/cake,/catering,/menu,/delivery,/store-locator - Key findings: WooCommerce API exposure, coupon code enumeration, custom order form injection, order data CSV export