What problem does it solve? Automated recon and ASM tools keyword-match on brand names, so for targets whose name is a common word, reports are dominated by assets belonging to unrelated same-named organizations. This Skill prevents wasting an engagement on out-of-scope assets and avoids accidentally attacking innocent third parties. ## Core Features & Use Cases - Ownership Verification: Applies per-source verification rules for GitHub repos, cloud buckets, mobile apps, breach combos, typosquats, and forum hits to separate owned assets from namespace collisions. - Soft-404 Detection: Uses a junk-path curl control to identify false-positive "Critical" findings (.env, .git, phpinfo) caused by SPA catch-all responses. - Severity Re-baselining: Re-counts findings against only verified-owned assets and quarantines collisions into auditable loot files. - Use Case: You receive an ASM report with hundreds of "Criticals" for a target named "Apex". Run this triage first to confirm the owned domain set, discard unrelated repos/buckets/apps, and re-baseline severity before any testing begins. ## Quick Start Triage this ASM report for the target and separate verified owned assets from same-name collisions before I start testing.