shodan-reconnaissance
Conduct Authorized Shodan Reconnaissance
Exposed internet assets create risk when teams cannot see them. This skill provides Shodan workflows for authorized searches, filters, exports, and reports.
Stop for confirmation before installing.
Review the plan and obtain explicit user consent before changing files.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "shodan-reconnaissance" from https://skillstore.io/skills/sickn33-shodan-reconnaissance.md and its manifest at https://skillstore.io/api/skills/sickn33-shodan-reconnaissance/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "shodan-reconnaissance". Find exposed services for an owned example.com domain.
Expected outcome:
A concise asset inventory with hostnames, IP addresses, observed ports, products, versions, and validation steps.
Using "shodan-reconnaissance". Summarize Shodan results for an authorized cloud IP range.
Expected outcome:
- Exposure summary grouped by service and region.
- Likely stale records separated from current scan candidates.
- Recommended owner validation and remediation priorities.
Using "shodan-reconnaissance". Prepare a report from downloaded Shodan data.
Expected outcome:
A human-readable report outline with findings, affected assets, evidence notes, limitations, and authorized follow-up actions.
Security Audit
High RiskMost Ruby backtick, API-key, hardcoded-IP, and certificate findings are documentation false positives because they are Markdown examples or placeholders. Confirmed issues include the elevated installation command, Shodan API network calls, and reconnaissance workflows for active scanning and exposed vulnerable services. No prompt injection attempt was found in SKILL.md.
Confirmed security concerns (6)
Capability review items (4)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (97)
🌐 Network access (18)
🔑 Env variables (5)
Detected Patterns
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/sickn33-shodan-reconnaissance/audits/5?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/sickn33-shodan-reconnaissance?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/sickn33-shodan-reconnaissance?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/sickn33-shodan-reconnaissance/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/sickn33-shodan-reconnaissance.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA · BibTeX · CFF)
APA citation
sickn33. (2026). shodan-reconnaissance security audit report (audit version 5) [Author version 1.1]. Skillstore. https://skillstore.io/skills/sickn33-shodan-reconnaissance/audits/5BibTeX citation
@techreport{sickn33-sickn33-shodan-reconnaissance-2026,
author = {sickn33},
title = {shodan-reconnaissance security audit report (audit version 5)},
institution = {Skillstore},
year = {2026},
number = {5},
url = {https://skillstore.io/skills/sickn33-shodan-reconnaissance/audits/5},
note = {Author version 1.1}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "shodan-reconnaissance security audit report (audit version 5)"
version: "1.1"
type: report
authors:
- name: "sickn33"
date-released: "2026-07-07"
url: "https://skillstore.io/skills/sickn33-shodan-reconnaissance/audits/5"
identifiers:
- type: other
value: "skillstore:sickn33-shodan-reconnaissance:audit:5"
description: "Skillstore immutable audit report identifier"
Skillstore Score
Why this score Evidence Confidence: MediumWhat You Can Build
External Exposure Review
Find public services for owned domains and networks before publishing an exposure report.
Pentest Reconnaissance Prep
Build an authorized target inventory with ports, products, versions, and likely vulnerabilities.
Incident Scoping
Search Shodan for exposed indicators, affected services, and public infrastructure during response.
Try These Prompts
Use this skill to plan a Shodan lookup for this authorized IP address: [IP]. Summarize expected fields and safe next steps.
Create Shodan queries for the owned domain [DOMAIN]. Include hostname, organization, product, and port filters with reporting notes.
Given these authorized targets [SCOPE], design Shodan searches for exposed vulnerable services and explain validation limits.
Build a full Shodan reconnaissance workflow for [CLIENT SCOPE]. Include authorization checks, credit use, exports, evidence handling, and final deliverables.
Best Practices
- Use only targets where you have written authorization.
- Store Shodan API keys outside prompts and shared files.
- Record query dates, filters, credits, and data freshness in reports.
Avoid
- Searching random vulnerable devices without permission.
- Treating stale Shodan data as proof without validation.
- Publishing raw banners, screenshots, or host lists that expose third parties.
Frequently Asked Questions
Does this skill run Shodan automatically?
Is this only for paid Shodan accounts?
Can it prove that a system is vulnerable?
How should API keys be handled?
Can it scan any public IP range?
What output should teams expect?
Developer Details
Author
sickn33License
MIT
Author version
v1.1
Skillstore revision
r1
Version notice
The author-declared version is not valid SemVer.
Repository
https://github.com/sickn33/antigravity-awesome-skills/tree/main/skills/shodan-reconnaissanceRef
9f814fc6a43fd99946f2da5e0df231c65a38bc76
Maintenance freshness
7/18/2026
Usage
9 downloads · 189 views
File structure
📄 SKILL.md