Shodan Reconnaissance and Pentesting
Discover exposed devices and vulnerable services via Shodan web, CLI, and API.
🛡️ AgentReady threat assessment
MAESTRO 7-layer threat model + OWASP AIVSS risk score for Shodan Reconnaissance and Pentesting, derived from its capabilities.
These scores are auto-generated from public information (the agent's own listing, docs, and repository) using the canonical OWASP AIVSS formula and the MAESTRO framework — an estimate for guidance, not a penetration test, audit, or certification. See the scoring methodology — every score is re-derived by the same automated method as an agent's public evidence changes.
Overview
An Agent Skill (author zebbern) for reconnaissance using Shodan: search filters, CLI, REST API, on-demand scanning, and network monitoring to find exposed services, vulnerable systems, and IoT devices. It guides the agent through internet-wide recon during pentest engagements, using a live external data source.
Key features and capabilities
- Shodan search-filter reconnaissance
- CLI and REST API querying
- IoT and open-port discovery
Use cases
- Finding exposed internet-facing devices
- Pentest reconnaissance