Recon automation pipeline
SkillMonitoring & opsChain recon tools into a repeatable, resumable pipeline for continuous bug-bounty coverage. Load on "automate recon", "recon pipeline", monitoring many programs, or scaling subdomain→ live→scan. Signals: wildcard scope at scale, wanting scheduled/continuous discovery.
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the Recon automation pipeline skill
What this skill tells your AI
The instructions your AI receives, as published by noorqureshi/sploitagent in skills/automation/automation-recon-pipeline/SKILL.md and read by ahel’s review.
When it applies
You track one or more wildcard programs and want discovery to run repeatably (and on a schedule), surfacing only new assets/findings instead of re-reviewing everything.
Why it works
Recon is a directed flow: roots → subdomains → resolve → live → ports → nuclei. Wiring the
ProjectDiscovery tools together (each reads/writes lines) makes it composable, and diffing
against last run (anew) turns it into continuous monitoring that alerts on change.
Method
- Pipeline (each stage feeds the next):
subfinder -dL roots.txt -all -silent \ | dnsx -silent -a -resp-only \ | httpx -silent -sc -title -tech-detect \ | tee live.txt \ | nuclei -silent -severity low,medium,high,critical - Diff for "only new": pipe each stage through
anew subs.txt/anew live.txtso reruns emit only newly-seen lines — the basis of continuous monitoring. - Notify: pipe results to
notify(Slack/Discord/Telegram) so new hosts/findings alert you. - Schedule with cron/systemd-timer/GitHub Actions; persist state files per program so runs resume.
- Keep templates current:
nuclei -update-templatesbefore each run.
Gotchas
- Stay in scope: feed only in-scope roots, filter out-of-scope hosts before scanning.
- Respect rate limits (
-rl,-c) and program automation rules — don't hammer. - De-dupe wildcard DNS (
dnsxwildcard filtering) or you'll alert on noise forever.
Verify success
A rerun surfaces only newly-appeared assets/findings and notifies you — hands-off continuous coverage.
References
ProjectDiscovery pipeline docs; TomNomNom anew; nuclei templates.
Signals
- GitHub stars
- 20
- Forks
- 7
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
automation-recon-pipeline- Source
- github.com/noorqureshi/sploitagent
github.com/noorqureshi/sploitagent
Related picks
Skill · countbot-ai
The pick for Croncron-packs
Skill · profbernardoj
The pick for Crongithub-actions
Skill · tddworks
The pick for GitHub Actionsgithub-actions-docs
Skill · devantler-tech
The pick for GitHub Actionswebhooks
Skill · nahid-sparktales
The pick for Webhooksadobe-webhooks-events
Skill · jeremylongshore
The pick for Webhooks