Concept of Operations document creation — executive summary, threat actor profiling, attack narrative, kill chain design, communication plan, deconfliction.
The CONOPS bridges the legal RoE and the tactical OPPLAN. It must be readable by a CEO while containing enough detail for operators.
plan/roe.json existsRead plan/roe.json first — scope and boundaries constrain the CONOPS.
See ../references/schema-quick-reference.md for the CONOPS, ThreatActor, KillChainPhase, and DeconflictionPlan schema fields.
Budget: 2 questions max for CONOPS/Threat Profile (soundwave.md CRITICAL_RULES → Question Budget). The remaining fields below are DEFAULTED or AGENT-DRAFTED, not asked — the tier table and RoE Constraint→Profile Implication table in threat-profile/SKILL.md already give deterministic defaults for motivation and initial access once the tier is picked, so re-asking them wastes a turn.
Question 1 — Threat actor tier (single-select, use threat-profile skill for detailed profiling):
Derive motivation and initial access vector from the picked tier via threat-profile/references/adversary-archetypes.md (default) — do not ask separately. Only deviate if the operator's free-text answer (via allow_other) already states a motivation/vector explicitly.
Question 2 — Success criteria — the crown-jewel / measurable win condition. Required; no default (every engagement needs an explicit end-state).
Agent-drafted, not asked:
CONOPS.communication_plan is DEPRECATED (see SCHEMA_REFERENCE in soundwave.md); ContactPlan (contact-template skill) owns this now. Asking about it here duplicates a question and writes to a dead field.deconfliction-template reference) unless the operator's RoE/contact answers already flagged a SOC integration endpoint; do not spend a dedicated question on it.Based on RoE scope + threat profile, select applicable phases. See references/kill-chain-templates.md.
Key rule: Don't include phases outside RoE scope. Recon-only engagement → only recon phase.
plan/conops.json — matching CONOPS schemaplan/deconfliction.json — matching DeconflictionPlan schemacommunication_plan is DEPRECATED — write coordination details to ContactPlan insteada04f96b
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.