Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIGitHub CopilotGitHub CopilotGemini CLIGemini CLI+20 more

    Passive Domain Recon

    1

    Passive domain reconnaissance using only Python's standard library: probe subdomains via DNS, pull certificate transparency records, inspect SSL certificates, r

    Free

    3 installsSecurity scanned
    Passive Domain Recon

    Passive Domain Recon

    Example session with this skill installed

    Perform passive recon on example-app.com. Check common subdomains and pull the latest certificate data. Output a CSV.

    • Read your context and instructions
    • Compiled the passive domain recon

    Generated recon report for example-app.com:
    subdomain,resolves_ip,in_ct_log,cert_expiry,http_server
    www.example-app.com,93.184.216.34,True,2025-08-14,nginx/1.18.0
    api.example-app.com,93.184.216.35,True,2025-05-20,Cloudflare
    dev.example-app.com,NXDOMAIN,True,2024-12-01,None

    Connects securely to your tools. The creator never sees your data.

    About this skill

    The problem

    Mapping a target's attack surface usually requires heavy third-party tools or aggressive active scanning that triggers alarms. Developers often need a quiet, dependency-free way to inventory subdomains and certificates without installing external binaries or Python packages.

    What it does

    • Enumerate subdomains using DNS resolution and Certificate Transparency logs via crt.sh.
    • Extract SSL certificate metadata including expiry dates and Subject Alternative Names (SAN).
    • Perform recursive WHOIS lookups by following IANA referrals to registrar servers.
    • Analyze HTTP response headers using benign HEAD requests to identify server stacks and security headers.
    • Generates a greppable CSV report of the findings for further pipeline processing.

    Frameworks & tools

    Python Standard Library (socket, ssl, urllib, json). No pip installs required.

    Why this beats prompting it yourself

    Writing reliable network code in Python requires specific error handling for DNS timeouts, TLS handshake failures, and WHOIS socket management. This skill provides a hardened, rate-limited workflow that avoids the common pitfalls of LLM-generated networking scripts like missing rate limits or improper socket closing.

    Use cases

    • Perform initial reconnaissance on a new project domain before a security audit.
    • Inventory all subdomains and their SSL certificate statuses for compliance.
    • Identify tech stacks and version disclosure via passive header analysis.
    • Monitor for certificate expiration across a distributed infrastructure.

    Known limitations

    Restricted to passive data sources. Does not perform port scanning, directory brute-forcing, or vulnerability testing. Requires internet access for crt.sh and WHOIS servers.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    3 installs

    Downloaded by developers to date

    Free forever

    No account required to browse

    Trust & safety

    Security scanned

    Verified clean 1 month ago

    • Free to download with an account

    Listed1 month ago
    Updated1 month ago

    What's inside

    Frequently Asked Questions