Recon Agent — Development agent for Claude Code
Subdomain enumeration and live host discovery specialist.
How to install Recon Agent
Installs to ~/.claude/agents/mikacr1138-claude-bug-bounty-recon-agent.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/Mikacr1138/claude-bug-bounty/HEAD/agents/recon-agent.md -o ~/.claude/agents/mikacr1138-claude-bug-bounty-recon-agent.md Restart Claude Code, or start a new session, for it to be picked up.
What Recon Agent does
name: recon-agent description: Subdomain enumeration and live host discovery specialist. Runs Chaos API (ProjectDiscovery), subfinder, assetfinder, dnsx, httpx, katana, waybackurls, gau, and nuclei. Produces prioritized attack surface for a target. Use when starting recon on a new target domain. tools: Bash, Read, Write, Glob, Grep model: claude-haiku-4-5-20251001
Recon Agent
You are a web reconnaissance specialist. When given a target domain, run the full recon pipeline and produce
Alternatives in Development
- Gitnexus Synthesis Critic — GitNexus final review synthesis critic 45.8k ★
- Recon Ranker — Attack surface ranking agent 4.5k ★
- Chaos Engineer 470 ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
Subfinder - Fast Passive Subdomain Enumeration Using Multiple Sources
subfinder -d target.com -all -o subdomains.txt amass enum -passive -d target.com -o amass_passive.txt assetfin
Subdomain Enumeration
subfinder -d {domain} -silent sort -u subs.txt amass enum -passive -d {domain} subs.txt sort -u subs.txt -o su
Takeover Hunter
Enumerates subdomain-takeover candidates for a previously-ingested program. Reads memory/programs/ .json, deri
Surface Discovery Agent
Runs bounded normal surface-discovery — subdomain enum, live hosts, archived/crawled URLs, nuclei, JS/JWT extr
Endpoint Hunter
Hunts publicly-exposed sensitive endpoints and files for a previously-ingested program (/.env, /config., /.git
GPT Pro
Surf GPT Pro advisory runner through the external-job provider bridge
Related Skills
Attack Surface
External attack-surface / recon audit of domains YOU OWN (your sites + subdomains, client sites under contract
Scan Cves
Run a focused nuclei CVE sweep against a host or recon directory, optionally filtered by year. Runs log4j-scan
Ext Recon
Launch the ext-enumerator agent to run passive+active recon and service/web enumeration against the in-scope t