← OGENIC GOD TOOLKITCONTENT HISTORY

Update to OGENIC GOD TOOLKIT

Snapshot Sep 30, 2026 · 23:15 UTC · version 1.2.4

Collection source: not recorded for this historical snapshot.

WHAT CHANGED · RULE-BASED ANALYSIS

First saved snapshot

No earlier snapshot is available to establish a change.

Compare saved observations

Download comparison JSON
Full technical diff · 0 changed fields
Full snapshot data
{
  "description": "Turn a netwalk scan record into a single self-contained HTML network report a site owner can be handed. Includes summary, method and coverage, embedded topology diagram, device inventory, per-device interfaces/VLANs/wireless/services/health, findings with evidence and recommendations, and the full log of commands run. Has a --public mode that strips internal detail. Use when the user asks for a network report, audit document, site survey writeup or something to deliver to a client.",
  "included_files": [
    {
      "relative_path": "agents/openai.yaml",
      "size_in_bytes": 203
    }
  ],
  "name": "netwalk-fullreport",
  "skill_md_contents": "---\nname: netwalk-fullreport\ndescription: Turn a netwalk scan record into a single self-contained HTML network report a site owner can be handed. Includes summary, method and coverage, embedded topology diagram, device inventory, per-device interfaces/VLANs/wireless/services/health, findings with evidence and recommendations, and the full log of commands run. Has a --public mode that strips internal detail. Use when the user asks for a network report, audit document, site survey writeup or something to deliver to a client.\n---\n\n# netwalk-fullreport\n\nPart of the **netwalk** read-only network survey toolkit. Toolkit lives at `{{TOOLKIT}}`.\n\nThis produces the thing that leaves the building. Treat it accordingly.\n\n## Run it\n\n```bash\nT={{TOOLKIT}}\nR=~/.netwalk/sites/acme-hq/scan-2026-08-22.json\n\npython3 $T/scripts/netwalk_report.py $R -o ~/.netwalk/sites/acme-hq/report.html\npython3 $T/scripts/netwalk_report.py $R -o ~/.netwalk/sites/acme-hq/report-public.html --public\n```\n\nOne self-contained HTML file: diagram, CSS and all. No external requests, so it works offline, over\nemail, and from a USB stick. It follows the reader's light/dark setting and prints sensibly.\n\n**The diagram is embedded at full size, not scaled to the column.** A 3000px site map squeezed into\na 1000px page is legible only as a shape — the hostnames, IP addresses and port names, which are the\nwhole reason to look at it, become unreadable. It scrolls sideways inside its own frame instead, and\nthe report offers a *Fit to width* toggle for readers who want the overview.\n\n## Full vs public\n\n| | Full | `--public` |\n|---|---|---|\n| Summary, topology, inventory, device detail | yes | yes |\n| Findings marked `public_safe: true` | yes | yes |\n| Findings marked `public_safe: false` | yes | **hidden** |\n| Evidence excerpts under each finding | yes | hidden |\n| Command log | yes | hidden |\n| Scan date, engineer name | yes | hidden |\n| Management-exposure detail | yes | hidden |\n\nAsk which one they want when it is ambiguous, and default to **full** — the person who ran the scan\nshould see everything. Send `--public` when the recipient is a landlord, a tenant, a procurement\ndepartment, or anyone who should see the shape of the network but not a list of ways into it.\n\n**`--public` is not redaction.** It hides sections; it does not sanitise text you wrote. If a\nfinding's title says \"admin/admin still works on the core switch\", `--public` will happily print it\nwhen `public_safe` is `true`. Set the flag correctly at the finding level in `netwalk-diag`.\n\n## The credential sweep\n\nBefore rendering, the record is swept for anything that looks like a secret — keys named\n`password`, `token`, `secret`, `community`, `psk`, `key_path` and friends, plus values containing\nprivate-key blocks, `password=` assignments, community strings under any prefix, or Cisco `secret`\nhashes. If anything matches, **the render is refused** with the exact JSON path.\n\n**This guarantee has failed once, so do not treat it as the only line of defence.** The pattern for\ncommunity strings was anchored on the word `snmp`, an evidence excerpt read `trap-community: <value>`,\nand the report rendered and was delivered with the string in it. The pattern is fixed and tested in\nboth directions now, but the lesson stands: the sweep catches shapes it knows. **Read the evidence\nexcerpts you write.** An excerpt exists to show the one line that proves a finding — if that line\nhappens to carry a value as well as a fact, cut the value out before it reaches the record.\n\nIf the user asks for the credentials so they can write up the site, that is a fair request and the\nanswer is not the report: `netwalk_cred.py export` writes them a separate 0600 access document, which\nby default carries the addresses, accounts and routes in without any secret values. The report stays\nclean either way.\n\nWhen that fires, fix the record — do not weaken the check. A secret in a customer-facing report is\nthe one failure in this toolkit that cannot be walked back once the file is sent.\n\n## Before you hand it over\n\nRead the rendered report as the recipient, not as the person who made it:\n\n1. **Is the coverage section honest?** `coverage.not_covered` becomes a visible \"what this report\n   does not cover\" box. If it is empty, that is a claim of completeness — is it true? A missing\n   subnet, a skipped RF survey, a device the user asked you not to touch all belong there.\n2. **Does every finding have evidence and a real recommendation?** \"Investigate further\" is not a\n   recommendation. Name the port, the setting, the next check.\n3. **Is the severity defensible?** Everything marked high reads as noise; nothing marked high when\n   the guest network is wide open is worse.\n4. **Does the diagram match the tables?** Both come from the same record, so a mismatch means the\n   record is internally inconsistent — usually an edge naming a `host_id` that no device uses.\n5. **Would a stranger understand the entry point and the scope?** `site.scope_note` is what says you\n   were authorised to be there.\n6. **Anything in there you would not want forwarded?** Config exports, PSKs and password hashes stay\n   on disk beside the record and never in the report.\n\n## Regenerating\n\nThe record is the source of truth. Never hand-edit the HTML — change the record and re-render, or\nthe next run silently discards your edit. The renderer is deterministic, so two scans of one site\nproduce diffable reports and a changed report means a changed network.\n\n## Telling the user what they got\n\nGive them the paths, say which mode each file is, and say plainly what is missing. If the crawl\nstopped early or three devices were unreachable, that goes in your message as well as in the\nreport — do not let a polished document imply a completeness the scan did not have.\n\n**Say where the survey left its sensitive files, every time.** The full report renders a *Where this\nsurvey left sensitive files* box in the Method section — the path to the credential store, the path\nto the config exports, and the fact that netwalk deletes neither of them by itself. Repeat it in\nyour message rather than assuming they read that box:\n\n- `~/.netwalk/creds/<slug>.json` — the credentials they typed into the login form, plain JSON,\n  file-permission protected and **not encrypted**. It survives the engagement until someone runs\n  `netwalk_cred.py forget --site <slug> --with-configs`, on **every machine the survey ran from** — a survey driven\n  from two boxes leaves two copies.\n- `~/.netwalk/sites/<slug>/configs/` — full config exports, containing PSKs, SNMP communities and\n  password hashes in clear text.\n\nThen offer to clear the credential store there and then. If any of those credentials are sensitive,\nsay that deleting is not the same as rotating: the shred overwrites the file, which on an SSD or a\ncopy-on-write filesystem is not a guarantee. The box appears in the full copy only — a customer\nreading the public copy has no business learning where the engineer keeps their passwords.\n\n## Never\n\n- Send or upload the report anywhere. Produce the file, hand over the path, let the user decide who\n  sees it.\n- Put credentials, config exports, PSKs or password hashes in it.\n- Present a partial survey as a complete one.\n"
}

SHA-256 of public snapshot: ec4f00fe7ac9d00e9a68c707030eb0f3e03cdf7857c714addfcbf0253a57bfd2