Passive, headless recon of a web app's frontend to infer its backend and tech stack - API endpoints, third-party vendors, CSP allow-lists, auth provider, framework/build tooling, and public config tokens - then produce a plain-English vendor dossier (Artifact + landscape PDF). Use this whenever the user wants to know what a web app is "built on", "runs on", or "uses under the hood", asks you to fingerprint / profile / tear down / map a competitor's or vendor's stack, wants to enumerate a site's APIs, endpoints, or third-party services from its JavaScript, or asks "what's their backend / what platforms do they use" for a URL like app.example.com - even if they don't say "r…