Ext Recon — Development skill for Claude Code
Launch the ext-enumerator agent to run passive+active recon and service/web enumeration against the in-scope targets, producing a structured inventory for the attack planner.
How to install Ext Recon
Installs to ~/.claude/skills/xcoy0te-claude-externalpentest-ext-recon/SKILL.md
mkdir -p ~/.claude/skills/xcoy0te-claude-externalpentest-ext-recon && curl -fsSL https://raw.githubusercontent.com/xcoy0te/Claude-ExternalPentest/HEAD/commands/ext-recon.md -o ~/.claude/skills/xcoy0te-claude-externalpentest-ext-recon/SKILL.md Restart Claude Code, or start a new session, for it to be picked up.
What Ext Recon does
description: Launch the ext-enumerator agent to run passive+active recon and service/web enumeration against the in-scope targets, producing a structured inventory for the attack planner.
Run reconnaissance / enumeration against the scoped targets.
**Authorized engagements only.** This reads the active engagement's `scope.md`; if no engagement exists, tell the operator to run `/ext-scope ` first and stop.
Steps:
- Resolve the active engagement directory (
$EDIR). Engagem
Alternatives in Development
- Auto Update — Pull the latest ECC repo changes and reinstall the current managed targets 243.5k ★
- JWT Scan — JWT attack toolkit (offline) — alg:none forgery, RS256→HS256 algorithm confusion, weak-secret crack, static cl 4.5k ★
- /surface — View the prioritized attack surface for a target 1.8k ★
Full documentation available on GitHub
View Source RepositoryRelated Skills
Ad Recon
Launch the ad-enumerator agent to run the collection phase against the defined scope, producing a structured A
Ext Attack Paths
Launch the ext-attack-planner agent to reason from the enumerated exposures to likely footholds, then present
Ad Attack Paths
Launch the ad-attack-planner agent to reason low-privilege-to-Domain-Admin paths from the collected inventory
Engage.Recon
Execute Phase 1 - Reconnaissance and Attack Surface Mapping
Ad Enum
Active Directory enumeration on: $ARGUMENTS
False Green
Agent skill for the checks that pass while the thing is broken. Seven false-green signals with fixes, plus thr
Related Agents
Ext Enumerator
Runs the RECON + ENUMERATION phase of an authorized external penetration test against the in-scope targets (IP
Ad Attack Planner
Reasons about low-privilege-to-Domain-Admin paths in an authorized Active Directory assessment. Takes the enum
Zp Recon Sweep
ZeroProtocol passive recon fan-out. Use to enumerate a target's attack surface from third-party sources only -