What problem does it solve? Automated recon and ASM tools keyword-match on brand names, so for targets whose name is a common dictionary word, reports are flooded with assets belonging to unrelated same-named companies. Acting on this untriaged data wastes the engagement and risks attacking innocent third parties outside scope. ## Core Features & Use Cases - Ownership Verification: Apply per-source verification rules for GitHub repos, cloud buckets, mobile apps, breach combos, typosquats, and forum hits to prove an asset belongs to the target before testing. - Soft-404 Detection: Run a junk-path control with curl to expose false-positive ".env", ".git", and admin-panel "Criticals" caused by SPA catch-all routes. - Severity Re-baselining: Recount findings against only-owned assets, quarantine collisions in auditable files, and surface the meta-finding when the ASM feed is mostly noise. - Use Case: You receive an ASM report with hundreds of "Criticals" for a target named "Apex". Use this Skill to confirm the owned-domain set, verify each asset class, discard same-named third-party repos and buckets, and reduce the report to the handful of genuinely owned findings. ## Quick Start Triage this ASM report for my target and separate verified owned assets from same-named third-party collisions before I start testing.