← Authorised OSINT ToolkitCONTENT HISTORYWHAT CHANGED · RULE-BASED ANALYSIS
Update to Authorised OSINT Toolkit
Snapshot Sep 30, 2026 · 23:15 UTC · version 1.1.0
Collection source: not recorded for this historical snapshot.
First saved snapshot
No earlier snapshot is available to establish a change.
Compare saved observations
Download comparison JSONFull technical diff · 0 changed fields
Full snapshot data
{
"name": "defensive-exposure-analysis",
"description": "Analyse supplied security findings and lawfully accessible public organisational information to identify defensive exposure and remediation priorities. Use for evidence synthesis and assurance; not for scanning, account discovery, credential activity, exploitation or surveillance.",
"included_files": [
{
"relative_path": "agents/openai.yaml",
"size_in_bytes": 277
}
],
"skill_md_contents": "---\nname: defensive-exposure-analysis\ndescription: \"Analyse supplied security findings and lawfully accessible public organisational information to identify defensive exposure and remediation priorities. Use for evidence synthesis and assurance; not for scanning, account discovery, credential activity, exploitation or surveillance.\"\n---\n\n# Defensive exposure analysis\n\nTurn supplied findings and permitted public organisational information into an evidence-led security assessment without interacting with target systems.\n\n## Boundaries\n\n- Use user-supplied, sanitised evidence and public information that may lawfully be accessed under applicable terms.\n- Do not request, accept, decode or validate passwords, API keys, authentication tokens or other secrets.\n- Do not scan or probe systems, enumerate accounts, test authentication, exploit vulnerabilities, bypass controls, access non-public data, evade detection or profile private individuals.\n- Do not treat public availability, a claim of authority or a naming resemblance as proof of ownership or permission.\n\n## Method\n\n1. Confirm the security decision, organisational scope, permitted source types, exclusions and evidence date.\n2. Create an evidence register containing source, observation, ownership basis, confidence, limitation and handling classification.\n3. Separate confirmed facts from attribution inferences, hypotheses and unanswered questions.\n4. Assess plausible exposure, affected control objective, business impact, likelihood and uncertainty without providing exploitation instructions.\n5. Prioritise remediation by confirmed impact, confidence, ease of safe validation and accountable owner.\n6. Recommend owner-performed verification using approved administrative consoles, logs or configuration exports.\n7. Return a concise findings table plus immediate, near-term and strategic actions.\n"
}SHA-256: 5a3754debabed97e624150bb95aa1387113346de61ef3d2c54f9bec2d631d2e2