All Skills Library · Recon

governed-recon

Passive-only exposure assessment. No exploitation.

Version
1.0.0
Lifecycle
reference
License
Apache-2.0
Published
2026-08-27
Reviewed
2026-08-27
Source
witnessops/witnessops-web
content/witnessops/skills/governed-recon/SKILL.md
Bytes
1098
SHA-256
15b91bee17d127c93226538e6b60cf857acf1c4b636192a24d4e43a260f4dbff
Plain view · SKILL.mdUTF-8 · exact download bytes
---
name: governed-recon
description: >
  Use for passive-only public exposure assessment of one authorised system.
  No credentials, no exploitation, no destructive testing. Stop when the next
  step would send an intrusive probe.
---

# Governed recon

See what the internet sees. Do not become the internet's attacker.

## Scope

- One authorised public-facing system
- Passive collection and documented public records
- Named unknowns when a check cannot be completed

## Workflow

1. Confirm the authorised target and the written scope.
2. Collect only passive public signals.
3. Record each observation with a source and a timestamp.
4. Name every unknown. Do not fill gaps with inference presented as fact.
5. Hand over an evidence-linked note, not a score.

## Guardrails

- Do not exploit.
- Do not use credentials or internal access.
- Do not run destructive tests or continuous monitoring.
- Do not expand scope to neighbouring hosts without a new authorisation.
- Do not call this a pentest.

## Outputs

- authorised target
- observations with sources
- named unknowns
- handover note
Governed recon — WitnessOps Skills