recon-quickFast OSINT and reconnaissance presets using bbot and nmap. One-command subdomain enumeration, port scanning, and web fingerprinting for bug bounty recon.
Install via ClawdBot CLI:
clawdbot install hostilespider/recon-quickGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Generated May 7, 2026
A bug bounty hunter uses Recon Quick to rapidly enumerate subdomains of a target program, discovering hidden entry points for further vulnerability research. The tool automates bbot for subdomain discovery and nmap for port scanning, saving hours of manual work.
A penetration tester runs a full preset against a client's domain to map the external attack surface, including subdomains, live hosts, open ports, and web technologies. The structured output integrates into reporting tools for comprehensive assessments.
A red team member deploys Recon Quick during the reconnaissance phase of an engagement to gather intelligence on target infrastructure. The passive preset allows discreet data collection without triggering alerts, while the full preset provides a detailed footprint for attack planning.
A security operations center (SOC) schedules Recon Quick runs weekly to monitor changes in their organization's external footprint, detecting new subdomains or exposed services that may indicate shadow IT or misconfigurations. The JSON output feeds into SIEM for correlation.
A cybersecurity researcher uses Recon Quick to collect data on subdomain enumeration techniques and service fingerprinting for a study on internet-wide scanning. The tool's presets and output structure facilitate reproducible experiments and data analysis.
Offer a free, limited version of Recon Quick for individual researchers, while providing a premium SaaS platform with additional features like scheduled scans, team collaboration, and API integration. Revenue comes from subscription tiers for enterprise teams.
Use Recon Quick as a value-add tool in penetration testing or red team consulting engagements. Offer training workshops on bug bounty and reconnaissance using the tool as a practical example. Revenue from consulting fees and training course sales.
Maintain the core Recon Quick as open-source to build community and adoption, then sell proprietary plugins for advanced features like cloud integration, custom presets, or AI-powered analysis. Revenue from plugin licenses and enterprise support contracts.
💬 Integration Tip
Easily integrate into CI/CD pipelines by running the tool via command line and parsing the JSON output; for deeper integration, use the structured output to feed findings into platforms like Nuclei or DefectDojo.
Scored Jun 20, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...