robotshell/magicRecon
MagicRecon is a powerful shell script to maximize the recon and data collection process of an objective and finding common vulnerabilities, all this saving the results obtained in an organized way in directories and with various formats. observed · 2026-08-28
Health v2 · maintenance only
23/100
- Activity 0
- Release rhythm 8
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 2478
- days_rel: n/a
- days_push: 771
- n_releases_24m: 0
Adoption not part of the score
1052 stars · 162 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
MagicRecon is a Bash shell script that automates reconnaissance and vulnerability scanning of target domains, including subdomain enumeration, port scanning, and checks for XSS, SQLi, subdomain takeover, and other common issues. It organizes results into directories in multiple formats, making it popular for bug bounty workflows.
Use cases
- automate recon on a target domain for a bug bounty
- enumerate subdomains and check which are alive
- scan a domain for XSS and SQL injection vulnerabilities
- find open ports and directories on a web target
- check for subdomain takeover and CORS misconfigurations
- collect whois, DNS, and certificate info for subdomains
- run recurring Nuclei vulnerability scans and save organized reports
When to choose
- you want an all-in-one automated recon and vulnerability scanning script for bug bounty
- you need organized, multi-format output from many recon tools in one run
- you work on Linux and are comfortable with Bash-based tooling
When to avoid
- you need a maintained library or API to integrate into your own code
- you require a GUI or Windows-native tool
- you need guaranteed accuracy — automated vulnerability checks produce false positives that require manual verification
Facets
cli-tool · maturity active
vulnerability-scanning web-scraping security osint cli security penetration-testing osint cli recon bugbounty subdomain-enumeration nuclei bash-script xss sql-injection subdomain-takeover command-line linux
1 source
- readme: https://github.com/robotshell/magicRecon · fetched 2026-08-28 · d740c33c0802
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| robotshell/magicRecon | main | 23 |
For agents
markdown · JSON · MCP: product_card(name="robotshell/magicRecon")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem