recon-cafes
Installation
SKILL.md
RECON-CAFES — Sector-Specific Recon for Coffee Shop & Cafe Sites
When to Use
Use when the target scope includes coffee shops, cafes, tea houses, or coffee roaster company domains. These small businesses run marketing sites with online ordering systems, loyalty programs (often custom or third-party), catering menus, and multiple location finders. Common vulnerabilities: online ordering API exposure, loyalty points manipulation, exposed Toast/Square API keys in JS bundles, store locator data leakage, and third-party integration misconfigurations.
Quick Reference
- Common CMS: WordPress (dominant), Squarespace, Wix
- Common platforms: Toast POS, Square Online, ChowNow, Olo, Clover, Upserve, Bbot, Ritual
- Key endpoints:
/order,/menu,/catering,/locations,/rewards,/loyalty,/gift-cards,/shop - Key findings: Toast POS API keys in JS bundles, online ordering API IDOR, loyalty program manipulation, store locator data exposure