ops-authorization-methodologylisted
Install: claude install-skill JZKK720/cubecloud-skills-bundle-kit
# Ops Authorization Methodology
## Scope Gate
### Confirm scope.md before any task start
- `scope.md` must exist under the current project root
- `auth.status` must be `granted`
- `network_profile.mode` must be set to one of:
- `offline` — no external network, only local files / VMs
- `lab_only` — only lab/CTF network segments
- `authorized_target_only` — only in-scope assets listed in `in_scope.assets`
- `unrestricted_lab` — only with written authorization for an isolated experiment network
If `scope.md` is missing or `auth.status != granted`, **STOP** and report scope deficiency. Do not proceed with any analysis or tool invocation.
## In-Scope and Out-of-Scope Assets
### in_scope.assets
List every host, domain, APK path, binary, URL, or service that is authorized for analysis.
- If `in_scope.assets` is empty **and** no offline sample path is set, **STOP** and report asset deficiency.
- Review `in_scope.assets` before any recon, reverse, or exploit activity.
### out_of_scope.assets
List activities and assets explicitly NOT authorized.
- Do not act on any asset not in `in_scope.assets` or `out_of_scope.assets`.
- If an activity would cross into `out_of_scope`, halt and re-evaluate scope.
## Network Profile
### network_profile.mode
Select the appropriate mode before any network-dependent step:
| Mode | Allowed | Prohibited |
|------|---------|------------|
| `offline` | Static analysis, local files, simulation | Any external network connection, public RP