google-dorks-catalog
High-precision Google dorks for exposed configs, secrets, and credentials -- real-world validated
Install / Use
npx skills add uphiago/recon-skills --skill google-dorks-catalogInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
Development & EngineeringSupported Platforms
Tags
Our assessment of google-dorks-catalog
google-dorks-catalog scores 86/100 on our quality scale, 1743rd of 4,259 Development & Engineering skills we index (top 41%).
Its SKILL.md is 4.1 KB long, well organised into 29 sections with 14 code examples: a solid amount of guidance for an agent.
With 1,280 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated 29 days ago, so google-dorks-catalog is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
google-dorks-catalog compared with similar skills
All 4 of these similar skills score higher than google-dorks-catalog; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| google-dorks-catalog (this skill)by uphiago | 86 | 1.3k | 29d ago | SKILL.md |
| ai-job-searchby MadsLorentzen | 100 | 44.6k | 1d ago | CLAUDE.md |
| claude-howtoby luongnv89 | 100 | 41.7k | today | CLAUDE.md |
| algorithmic-artby anthropics | 100 | 177.9k | 8d ago | SKILL.md |
| pptxby anthropics | 100 | 177.9k | 8d ago | SKILL.md |
Frequently asked questions
- How do I install google-dorks-catalog?
- Run
npx skills add uphiago/recon-skills --skill google-dorks-catalog. The install tabs above show the steps for each supported agent. - Which AI agents does google-dorks-catalog work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is google-dorks-catalog safe to use?
- It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is google-dorks-catalog still maintained?
- The repository was last updated 29 days ago, so google-dorks-catalog is actively maintained.
Skill content
View source on GitHubname: google-dorks-catalog description: "High-precision Google dorks for exposed configs, secrets, and credentials -- real-world validated" version: 1.1.0 revision_date: 2026-07-25 license: MIT platforms: [linux] compatibility: N/A (reference catalog) disable-model-invocation: true tags: [meta, google-dorks, secrets, passive-recon, osint] category: meta
Google Dorks Catalog -- Exposed Configs & Secrets
When to Use
- During passive reconnaissance (Phase 1) on every target
- After crt.sh subdomain enumeration
- Before any active scanning
- Validated against 100+ real targets
High-Precision Dorks
Critical Exposed Files
site:$target "APP_KEY"
site:$target "DB_PASSWORD"
site:$target "-----BEGIN RSA PRIVATE KEY-----"
site:$target filetype:env
site:$target inurl:git/config
site:$target intitle:"index of" ".env"
site:$target "api_key" OR "apikey" OR "secret_key"
site:$target "firebase" "apiKey"
site:$target "supabase" "anon" "key"
site:$target inurl:"/.env" "DB_PASSWORD"
site:$target "client_secret" "redirect_uris" extension:json
site:$target "private_key" "client_email" extension:json
Exposed Configuration Files (ALL Extensions)
site:$target ext:log | ext:txt | ext:conf | ext:cnf | ext:ini | ext:env | ext:sh | ext:bak | ext:backup | ext:swp | ext:old | ext:~ | ext:git | ext:svn | ext:htpasswd | ext:htaccess | ext:json
This covers:
- logs -- tokens, SQL queries, emails in plain text
- txt/conf/cnf/ini -- server configurations, DB hosts
- env -- environment variables with credentials
- sh -- scripts with hardcoded passwords
- bak/backup/swp/old/~ -- backup files with old versions
- git/svn -- exposed versioned repositories
- htpasswd/htaccess -- access control with hashes
- json -- service accounts, Firebase configs, Supabase configs
Service-Specific Dorks
Supabase
site:$target "supabase.co" "anon_key" OR "SUPABASE_ANON_KEY"
Firebase
site:$target "firebase-adminsdk" "private_key_id" extension:json
AWS
site:$target "AKIA" filetype:env NOT example NOT test
SendGrid
site:$target "SG." filetype:env NOT example
MongoDB
site:$target "mongodb+srv://" "password"
PostgreSQL
site:$target "postgresql://" "password" ext:env
JWT Secrets
site:$target "JWT_SECRET" OR "jwt_secret" filetype:env
OpenAI API Keys
site:$target "sk-" filetype:env OR filetype:txt
GitHub Tokens
site:$target "ghp_" OR "gho_" OR "ghu_"
GitHub Code Search Patterns
With GitHub personal token (much better results):
headers = {"Authorization": "token GH_TOKEN"}
base = "https://api.github.com/search/code"
# SA Keys (Firebase/GCP) -- ~1 in 30 is valid
params = {"q": '"type": "service_account" "private_key" "project_id"'}
# .env with real credentials
params = {"q": 'DB_PASSWORD+DB_HOST+APP_KEY+filename:.env+NOT+example+NOT+your+NOT+test'}
# Supabase URLs + keys
params = {"q": 'supabase.co+SUPABASE_URL+SUPABASE_ANON_KEY+NOT+example+NOT+your'}
# AWS Keys
params = {"q": 'AKIA+filename:.env+NOT+example+NOT+your'}
# SendGrid keys
params = {"q": 'SG.+filename:.env+NOT+example'}
# MongoDB connection strings
params = {"q": 'mongodb+srv://+password+filename:.env'}
Certificate SAN Discovery
# Extract SANs directly from the certificate
openssl s_client -connect $TARGET:443 -servername $TARGET </dev/null 2>/dev/null | \
openssl x509 -noout -ext subjectAltName | grep -Eo 'DNS:[^,]+' | cut -d: -f2 | sort -u
Real-World Cases
Real-world case (redacted): SSO certificate revealed ORG_DOMAIN_1, ORG_DOMAIN_2, ORG_DOMAIN_3 that didn't appear in conventional CT searches.
Pitfalls
| Issue | Solution | |-------|----------| | Google rate limits | Space out searches, use incognito, rotate IP | | GitHub API limits | Use personal token (5000 req/hr) | | False positives from example repos | Append NOT example NOT test NOT your |
Verification
# Test dork results manually
curl --max-time 30 --connect-timeout 10 -sk "https://$TARGET/.env" | head -5
# Verify GitHub found secrets
python3 -c "import json; print(json.loads(open('result.json').read()))"
Related Skills
ai-job-search
44.6kThe job search that runs on your machine. AI job application framework built on Claude Code: evaluate postings, tailor CVs, write cover letters, prep interviews. Fork it and own it.
claude-howto
41.7kA visual, example-driven guide to Claude Code — from basic concepts to advanced agents, with copy-paste templates that bring immediate value.
algorithmic-art
177.9kCreating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems.
pptx
177.9kUse this skill any time a .pptx or .potx file is involved in any way — as input, output, or both. This includes: creating slide decks, pitch decks, or presentations; reading, parsing, or extracting text from any .pptx or .potx file (even if the extracted content will be used elsewhere, like in an em…
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
