
Technical ability cannot compensate for unsafe credential handling, unauthorized access or disclosure of restricted information.
Use only assigned accounts, systems, channels and commands. Do not explore additional access, test production permissions or retain access after its purpose ends.
Restricted information includes private reports, logs, IP or host information, account details, candidate records, internal channels, examination material, incident notes, access plans and security configuration.
If a password, token, key or private link is exposed, stop using it, notify the responsible administrator, revoke or rotate it, preserve necessary evidence privately and document the incident.
Testing requires explicit scope and a safe environment. Record initial state, make only approved changes, remove temporary bans or access, restore modes and verify the final state.
Report suspected compromise, unauthorized access, malware, leaked records, unsafe commands or accidental disclosure immediately. Do not quietly delete evidence or attempt unsupported recovery.