# recon - Agent Ruleset

> **Skills**: on-demand rulesets live in [`../skills/`](../skills/); the full
> list is the SKILLS CATALOGUE in the [root AGENTS.md](../AGENTS.md). The table
> below is generated by `sync.sh` - never hand-edit it.

### Auto-invoke Skills

When performing these actions, ALWAYS invoke the corresponding skill FIRST:

| Action | Skill |
| ------ | ----- |
| Adding a new tool to the recon pipeline | `recon-tool-integration` |
| Adding or editing a recon/helpers/ai_planner hook or its /llm endpoint | `recon-ai-enrichment` |
| Adding partial-recon support for a recon tool | `add-partial-recon` |
| Changing or adding a project setting or default value | `project-settings-cascade` |
| Editing SECTION_INPUT_MAP or the partial-recon modal wiring | `add-partial-recon` |
| Editing a Prisma @default, a Python settings default, or the /defaults endpoint | `project-settings-cascade` |
| Editing recon execution groups, enrichment modules, or the recon image list | `recon-tool-integration` |
| Wiring an LLM into a recon tool's decisions (AI in pipeline) | `recon-ai-enrichment` |

---

## CRITICAL RULES - NON-NEGOTIABLE

<!-- Add a rule only if an agent breaks it while working elsewhere AND cannot
     discover it from the file being edited. Component patterns belong in a
     scoped skill. See the root AGENTS.md for repo-wide rules. -->

---

## TECH STACK

Python 3.11 recon pipeline. Runs in the `redamon-recon` image, **spawned fresh
per scan job** (source is volume-mounted at spawn - no rebuild needed for a
`.py` change). Wraps external tools (nuclei, katana, ffuf, gau, ...).

## PROJECT STRUCTURE

```
main.py                    full-pipeline entrypoint
partial_recon.py           partial-recon entrypoint
main_recon_modules/        per-tool modules for the full pipeline
partial_recon_modules/     per-tool modules for partial recon
helpers/                   shared helpers (incl. helpers/ai_planner/ AI enrichment)
graphql_scan/  cache_scan/ specialized probes
wordlists/  data/          static assets
tests/                     pytest (redamon-recon image; sections `recon` + `root-recon`)
```

## COMMANDS

```bash
# recon runs inside the redamon-recon image; use the repo gate
./redamon.sh test unit        # includes the `recon` and `root-recon` sections
```

## QA CHECKLIST

- [ ] `./redamon.sh test unit` green (recon + root-recon sections).
- [ ] New or changed behaviour is covered by a test (see the `redamon-testing` skill for where + how).
- [ ] New tool/feature works in BOTH the full pipeline AND partial recon.
- [ ] Mirrored an existing module's pattern rather than inventing a new one.
- [ ] AI-enrichment paths never raise (fall back to the user's current value).
