Ross ROSS = Recommend OSS · open-source software intelligence for agents

uphiago/recon-skills resource

Recon & pentest skill pack. CORS, XSS, SQLi, SSRF, RCE, WordPress, MCP, cloud, subdomain takeover, and more. Field-tested. MIT. Full write-up at hiago.sh observed · 2026-08-28

github.com/uphiago/recon-skills · homepage · Python · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

58/100

  • Activity 99
  • Release rhythm 35
  • Longevity 5

Flags: no_releases young

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 70
  • days_rel: n/a
  • days_push: 9
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1199 stars · 209 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

A curated pack of Markdown skill files documenting reconnaissance and penetration-testing procedures for web apps, APIs, authentication, cloud, and infrastructure. It serves as a reference playbook collection for authorized security testing and bug bounty work rather than an executable tool.

Use cases

  • learn web application penetration testing methodology
  • find subdomain takeover and SSRF testing playbooks
  • structure a bug bounty recon workflow
  • reference OAuth and JWT attack techniques
  • plan an external attack-surface assessment
  • validate CORS, XSS, and SQLi vulnerabilities during engagements

When to choose

  • you need field-tested step-by-step pentest and recon procedures
  • you run authorized bug bounty or red team engagements and want a methodology reference
  • you want documented prerequisites, pitfalls, and verification criteria per technique

When to avoid

  • you expect runnable scanning or exploitation tooling - this is documentation, not a scanner
  • you lack authorization to test the target systems
  • you need automated continuous security monitoring

Facets

learning-resource · maturity active

penetration-testing security osint vulnerability-scanning developer-tools security penetration-testing osint developer-tools cli python bug-bounty red-team reconnaissance skill-pack markdown-playbooks offensive-security subdomain-enumeration ssrf wordpress-security jwt-attacks linux

2 sources

Member repositories

RepositoryRoleHealth v2
uphiago/recon-skillsmain58

For agents

markdown · JSON · MCP: product_card(name="uphiago/recon-skills")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem