Recon — Research agent for Claude Code
Maps a repository's attack surface — structure, entry points, dependencies, trust boundaries.
How to install Recon
Installs to ~/.claude/agents/rmrosec-vulnswarm-recon.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/rmrosec/vulnswarm/HEAD/agents/recon.md -o ~/.claude/agents/rmrosec-vulnswarm-recon.md Restart Claude Code, or start a new session, for it to be picked up.
What Recon does
name: recon description: Maps a repository's attack surface — structure, entry points, dependencies, trust boundaries. Use this first on any new target before deeper analysis. model: sonnet tools: Read, Bash, Grep, Glob, Write maxTurns: 40
You are a security reconnaissance agent. Your job is to rapidly map a repository's attack surface so that deeper analysis agents know where to focus.
Given a repository path, produce two outputs:
.vulnswarm/attack-surface.json— structured
Alternatives in Research
- Attack Tree Construction — Systematic attack path visualization and analysis 31.9k ★
- Cross Role Reviewer — Compares Decision Digests across role analysis files in a brainstorm session to surface conflicts, gaps, and s 530 ★
- Echo Analyst — Use this agent BEFORE planning to surface requirement gaps, hidden assumptions, and missing acceptance criteri 523 ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
Specflow Codebase Scanner
Codebase exploration specialist for SpecFlow discovery and analysis phases. Use for finding relevant files, pa
Redteam Commander
Red team engagement lead. Owns research, planning, multi-domain grow-agent dispatch, cross-target synthesis, a
Exploit Researcher
Vulnerability research agent — identifies CVEs, finds exploit PoCs, maps attack chains, and develops custom ex
Osint Shadow
The Shadow, the adversarial intelligence operator. Attack-surface and exposure analysis that finds what target
Scope Exploit
Red team operator — context-driven permission discovery, escalation path identification with real-world resear
Page Object Mapper
Maps UFT objects to existing Aurora Page Object elements or proposes new ones, applying naming conventions and
Related Skills
Threat Model Skill
Claude Code skill: write the project's security constitution (assets, roles, trust boundaries, invariants, ent
Surface
Show ranked attack surface for a target from its recon manifest + hunt memory. Deterministic backing is cbh su
/recon
Run the full recon pipeline on a target and produce a prioritized attack surface.