← ClaudeAtlas

ops-authorization-methodologylisted

Authorization and scope methodology for security/penetration/red-team tasks. Read-only checklist: confirm scope.md, network_profile mode, in-scope/out-of-scope assets, deliverables, and stop/replan conditions. No scripts, no toolchain coupling.
JZKK720/cubecloud-skills-bundle-kit · ★ 3 · AI & Automation · score 69
Install: claude install-skill JZKK720/cubecloud-skills-bundle-kit
# Ops Authorization Methodology ## Scope Gate ### Confirm scope.md before any task start - `scope.md` must exist under the current project root - `auth.status` must be `granted` - `network_profile.mode` must be set to one of: - `offline` — no external network, only local files / VMs - `lab_only` — only lab/CTF network segments - `authorized_target_only` — only in-scope assets listed in `in_scope.assets` - `unrestricted_lab` — only with written authorization for an isolated experiment network If `scope.md` is missing or `auth.status != granted`, **STOP** and report scope deficiency. Do not proceed with any analysis or tool invocation. ## In-Scope and Out-of-Scope Assets ### in_scope.assets List every host, domain, APK path, binary, URL, or service that is authorized for analysis. - If `in_scope.assets` is empty **and** no offline sample path is set, **STOP** and report asset deficiency. - Review `in_scope.assets` before any recon, reverse, or exploit activity. ### out_of_scope.assets List activities and assets explicitly NOT authorized. - Do not act on any asset not in `in_scope.assets` or `out_of_scope.assets`. - If an activity would cross into `out_of_scope`, halt and re-evaluate scope. ## Network Profile ### network_profile.mode Select the appropriate mode before any network-dependent step: | Mode | Allowed | Prohibited | |------|---------|------------| | `offline` | Static analysis, local files, simulation | Any external network connection, public RP