← Browse
web-recon
qte77 ★ 2
This plugin enables authorized web and API reconnaissance through an end-to-end workflow that discovers attack surface, tests authentication posture, and identifies BOLA/BFLA vulnerabilities via the web-recon-kit harness. The underlying skill runs read-only operations (GET/OPTIONS) that are throttled and never trigger mutations or cron jobs.
Install
> /plugin marketplace add qte77/claude-code-plugins/tree/HEAD/plugins/web-recon
> /plugin install web-recon
Source: https://github.com/qte77/claude-code-plugins/tree/HEAD/plugins/web-recon
What it's made of
1 skill
- Commands
- 0
- Agents
- 0
- Skills
- 1
- MCP servers
- 0
- Hooks
- 0
What it needs & plugs into
- API keys
- none
- Paid services
- none detected
- External tools
- none
- Talks to
- nothing external detected
Facts extracted from the plugin's files. Prose generated by claude-haiku-4-5-20251001.
Is this your plugin?
Claim it to keep the card accurate and enter the weekly contest. Requires signing in as the GitHub owner (qte77).