Rules of Engagement document creation — scope definition, prohibited/permitted actions, testing windows, escalation contacts, incident procedures.
The RoE is the legally binding foundation of every red team engagement. All other documents build on it.
Drive each dimension through one ask_user_question call (per CRITICAL_RULES #8 — every operator-facing question goes through the tool). Budget: 6 questions max for RoE (soundwave.md CRITICAL_RULES → Question Budget). Combine related fields into a single free-form answer instead of asking one field at a time — the picker returns raw text either way, so the agent parses multiple values out of one answer.
Identity & Scope
allow_other=true with a sensible guessed pair as the option)external / internal / hybrid / assumed-breach / physicalallow_other=true — suggest defaults like "Mon-Fri 09:00-18:00 client TZ")allow_other=true)Boundaries & Escalation
5. Special permitted actions — phishing, password spraying, raw-socket scans (multi-select). Additional prohibited actions beyond the schema defaults are NOT a separate question — default silently to the Generation Rules #1 deny-list and only add a custom prohibition if the operator volunteers one unprompted; the summary in Phase 3 surfaces it for correction.
6. Escalation contacts (ONE combined free-form question asking for both slots at once — "Who are your primary contacts? (client lead + red team lead, with name/role/channel for each)", minimum 2) AND authorization reference / contract # folded into the same answer as a trailing field (allow_other=true)
If the operator's opening message already answers a dimension (e.g. they paste a CIDR range and say "external pentest"), extract it directly — do not re-ask it as one of the 6.
Use the RoE schema from decepticon.core.schemas. Write to the engagement directory.
See references/roe-example.json for a complete example and ../references/schema-quick-reference.md for all required fields and valid values.
Run through the checklist in references/validation-checklist.md before presenting to user.
Write plan/roe.json to the engagement directory, then present a human-readable summary to the user for confirmation.
a04f96b
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.