All Skills Library · Recon
governed-recon
Passive-only exposure assessment. No exploitation.
- Version
- 1.0.0
- Lifecycle
- reference
- License
- Apache-2.0
- Published
- 2026-08-27
- Reviewed
- 2026-08-27
- Source
- witnessops/witnessops-web
content/witnessops/skills/governed-recon/SKILL.md - Bytes
- 1098
- SHA-256
15b91bee17d127c93226538e6b60cf857acf1c4b636192a24d4e43a260f4dbff
Plain view · SKILL.mdUTF-8 · exact download bytes
--- name: governed-recon description: > Use for passive-only public exposure assessment of one authorised system. No credentials, no exploitation, no destructive testing. Stop when the next step would send an intrusive probe. --- # Governed recon See what the internet sees. Do not become the internet's attacker. ## Scope - One authorised public-facing system - Passive collection and documented public records - Named unknowns when a check cannot be completed ## Workflow 1. Confirm the authorised target and the written scope. 2. Collect only passive public signals. 3. Record each observation with a source and a timestamp. 4. Name every unknown. Do not fill gaps with inference presented as fact. 5. Hand over an evidence-linked note, not a score. ## Guardrails - Do not exploit. - Do not use credentials or internal access. - Do not run destructive tests or continuous monitoring. - Do not expand scope to neighbouring hosts without a new authorisation. - Do not call this a pentest. ## Outputs - authorised target - observations with sources - named unknowns - handover note