Content & endpoint discovery
SkillAI & modelsDiscover hidden paths, endpoints, params, and JS-exposed routes on a web target. Load after a live host is found, on "dirbust/content discovery/fuzzing", or when mapping an app's real surface. Signals: a single web host to deep-map, SPA with API calls, /api, JS bundles.
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the Content & endpoint discovery skill
What this skill tells your AI
The instructions your AI receives, as published by noorqureshi/sploitagent in skills/recon/recon-content-discovery/SKILL.md and read by ahel’s review.
When it applies
You have a live host and need its real surface: hidden dirs, backups, admin panels, API routes, and parameters — the inputs every other skill tests.
Why it works
Apps expose far more than the UI links to. Historical URLs, JS bundles, and predictable paths reveal endpoints (and params) that were never meant to be public or were left from old versions.
Method
- Passive URL mining first:
gau target.com+waybackurlspull historical URLs (old params, deprecated endpoints) with zero requests to the target. - Crawl, incl. JS:
katana -u https://target -jc -kf allorgospiderto extract links and endpoints embedded in JavaScript (SPAs hide the API here). - Directory/file brute:
feroxbuster -u https://target -w raft-medium-directories.txt -x php,txt,bak,zip,json— recursive; add extensions matching the stack. - Parameter discovery:
arjun -u https://target/endpointfinds hidden GET/POST params that feed injection tests (XSS/SQLi/IDOR). - Rank findings: admin/upload/import/debug/graphql/swagger routes and anything with params go to the front of the hunting queue.
Gotchas
- Auto-calibrate against soft-404s (
ffuf -ac, ferox filters) or you'll drown in false 200s. - Respect rate limits/program rules — throttle (
-t,--rate-limit) on live targets. - Pull params from JS and wayback; each finds ones the other misses.
Verify success
A prioritized list of reachable endpoints + parameters, feeding web-*/api-* hunting.
References
ProjectDiscovery katana; feroxbuster/ffuf docs; s0md3v Arjun; TomNomNom gau/waybackurls.
Signals
- GitHub stars
- 20
- Forks
- 7
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
recon-content-discovery- Source
- github.com/noorqureshi/sploitagent
github.com/noorqureshi/sploitagent
Related picks
Skill · thedaviddias
The pick for JavaScriptmodern-javascript-patterns
Skill · wshobson
The pick for JavaScriptcraft-php-guidelines
Skill · michtio
The pick for PHPfeature-flags-php
Skill · posthog
The pick for PHPcf-crawl
Skill · davila7
The pick for Crawlcrawling-a-site
Skill · xberg-io
The pick for Crawl