---
name: governed-recon
description: >
  Use for passive-only public exposure assessment of one authorised system.
  No credentials, no exploitation, no destructive testing. Stop when the next
  step would send an intrusive probe.
---

# Governed recon

See what the internet sees. Do not become the internet's attacker.

## Scope

- One authorised public-facing system
- Passive collection and documented public records
- Named unknowns when a check cannot be completed

## Workflow

1. Confirm the authorised target and the written scope.
2. Collect only passive public signals.
3. Record each observation with a source and a timestamp.
4. Name every unknown. Do not fill gaps with inference presented as fact.
5. Hand over an evidence-linked note, not a score.

## Guardrails

- Do not exploit.
- Do not use credentials or internal access.
- Do not run destructive tests or continuous monitoring.
- Do not expand scope to neighbouring hosts without a new authorisation.
- Do not call this a pentest.

## Outputs

- authorised target
- observations with sources
- named unknowns
- handover note
