{"id":19346,"plugin_id":"plugins_6a972043ba948191848287ee55e51b98","kind":"skill","collection_source":null,"comparison_source":null,"observed_at":"2026-09-30T23:15:30.416Z","digest":"3357df031ec97598b4d002d8ac47ac2fcc6a61944dcb643651041a82de27bd92","against":null,"payload":{"name":"exposure-risk-quantification","description":"Convert existing reconnaissance findings into transparent likelihood, impact, FAIR-style loss estimates, risk scores and executive reporting. Use for analysis and communication, not target collection or active testing.","included_files":[{"relative_path":"agents/openai.yaml","size_in_bytes":307},{"relative_path":"references/source-playbook.md","size_in_bytes":39783}],"skill_md_contents":"---\nname: exposure-risk-quantification\ndescription: \"Convert existing reconnaissance findings into transparent likelihood, impact, FAIR-style loss estimates, risk scores and executive reporting. Use for analysis and communication, not target collection or active testing.\"\n---\n\n# Exposure Risk Quantification\n\n## Authorisation and safety\n\n- Confirm the target is owned by the user or covered by written authorisation before sending target-directed traffic, executing bundled recon scripts, validating credentials, enumerating users, scanning ports or scheduling recurring checks. Record the exact in-scope domains, IP ranges, methods, rate limits and engagement window.\n- Passive analysis of user-supplied data and public documentation may proceed without target interaction. Clearly label unverified attribution and do not convert discovered sibling assets into scan scope.\n- Do not exploit vulnerabilities, bypass access controls, submit or replay credentials, perform password spraying, induce state changes, evade detection, send phishing messages, access non-public data or use destructive probes.\n- Treat exposed secrets and personal data as sensitive. Minimise collection, redact reports, avoid unnecessary validation and follow the engagement's evidence-handling and disclosure rules.\n- Stop when authorisation is absent or ambiguous, a technique would exceed scope, rate limiting or defensive blocking appears, or an action could materially affect a system. Ask for a narrower safe action.\n\n## Workflow\n\n1. Establish whether the request is passive analysis or involves target interaction. For interaction, capture the scope and authority required above before proceeding.\n2. Read [references/source-playbook.md](references/source-playbook.md), searching within it for the topic relevant to the request. Load only the relevant sections into working context.\n3. Prefer passive and keyless sources first. Separate observed facts, attribution inferences, hypotheses and proposed validation.\n4. Use bundled scripts only when they directly support the authorised task. Inspect their prerequisites and resolved target/output paths before execution; do not install dependencies or run network operations implicitly.\n5. Preserve source URLs, timestamps, commands, hashes and confidence so another analyst can reproduce the result. Redact secrets and unnecessary personal data from deliverables.\n6. Report scope, method, evidence, confidence, limitations, findings and proportionate next actions. Never represent a candidate asset, guessed identity, exposure or exploitability as proven without supporting evidence.\n\n## Source and licence\n\nThis adaptation preserves methodology from Sachin Sharma's `elementalsouls/Claude-OSINT`, pinned at commit `13d920413448c026b52ac74efee0f1eb39dd81ff`. See the package-level `ATTRIBUTION.md`, `LICENSE`, and `LICENSE-CONTENT`.\n"},"changes":[],"summary":"First saved snapshot. No earlier version is available for comparison.","summary_kind":"deterministic","summary_metadata":{}}