Subdomain Takeover skill: what it does and how to install it
Detects and verifies dangling DNS records that point to claimable cloud or SaaS resources, covering CNAME, NS, MX and wildcard risks.
Summary generated from the skill's documentation.
Install
$ npx skills add yaklang/hack-skills --skill subdomain-takeoverRun it in a terminal. If your agent is already running, start a new session so it picks the skill up.
About this skill
What it does. Enumerates subdomains, resolves CNAME, NS, MX and A records, and matches provider error responses to takeover fingerprints. It guides resource-claim verification for services such as S3, GitHub Pages and Heroku, then assesses cookie, email, OAuth and DNS impact alongside remediation.
When to use it. For authorised assessments of dangling DNS records and deprovisioned third-party resources. It distinguishes claimable records from active services, private buckets and other cases that do not indicate a takeover.
History
Repo stars
2.4k
Tracking since . A chart appears once there are 7 days of data.
Stars are counted for the whole repository, which holds 10 skills.
Installs
3.3k
Tracking since . A chart appears once there are 7 days of data.
Installs via skills.sh
Similar skills
- API and Interface DesignGuides the design of stable APIs and module boundaries, covering REST and GraphQL endpoints and type contracts between modules.
- Documentation and ADRsRecords architecture decisions as ADRs and keeps documentation current when public APIs change or features ship.
- Cloud Run BasicsManages Cloud Run services, jobs and worker pools for HTTP apps, scheduled tasks and background processing.