JavaScript analysis
SkillWeb & browsingMine JavaScript for endpoints, params, secrets, and hidden functionality. Load on SPAs, heavy JS apps, after crawling, or "analyze the JS". Signals: bundled JS (webpack/main.*.js), API calls in JS, source maps, /static/js, front-end frameworks.
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the JavaScript analysis skill
What this skill tells your AI
The instructions your AI receives, as published by noorqureshi/sploitagent in skills/recon/recon-js-analysis/SKILL.md and read by ahel’s review.
When it applies
The app is JS-heavy (SPA). The front-end bundle is a map of the backend: it references API endpoints, parameters, feature flags, roles, and sometimes secrets — much of it not linked in the UI.
Why it works
Client code must know how to call the server, so endpoints/params are embedded in JS. Bundlers also occasionally ship source maps (full original source) and developers leave keys/comments.
Method
- Collect all JS:
katana -jc,subjs, or crawl; grab every.js(incl. lazy-loaded chunks). - Extract endpoints/params:
linkfinder/jsluicepull URLs, paths, and param names from bundles. - Hunt secrets & flags: grep for
apiKey|token|secret|internal|admin|debug, feature flags, and role checks done client-side (server may not enforce them → BOLA/BFLA leads). - Source maps: if
.mapfiles ship, reconstruct original source (source-maptools) → full whitebox-ish view. - Feed results: new endpoints →
api-*; client-only auth checks →api-bola; secrets → validate.
Gotchas
- Client-side "admin" gating usually isn't enforced server-side — test the endpoints directly.
- De-obfuscate/beautify minified bundles before grepping (
js-beautify). - Lazy-loaded chunks hide the juicy routes — enumerate all chunk files, not just
main.js.
Verify success
Endpoints/params/secrets extracted from JS that weren't in the UI — new, testable surface.
References
LinkFinder/jsluice; katana; "JS recon" bug-bounty methodology.
Signals
- GitHub stars
- 20
- Forks
- 7
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
recon-js-analysis- Source
- github.com/noorqureshi/sploitagent
github.com/noorqureshi/sploitagent
Related picks
Skill · thedaviddias
The pick for JavaScriptmodern-javascript-patterns
Skill · wshobson
The pick for JavaScriptcf-crawl
Skill · davila7
The pick for Crawlcrawling-a-site
Skill · xberg-io
The pick for Crawlfirecrawl-build-scrape
Skill · firecrawl
The pick for Scrapescrape
Skill · davila7
The pick for Scrape