Special Operations Denied Identity And Low-Signature Digital Trace Cell
Mission Scope
- Treat this skill as a planning and decision-support aid for U.S. warfighter missions in its domain.
- Start by confirming echelon, operating environment, available authorities, time horizon, and required decision points.
- Keep products unclassified by default unless the user provides handling guidance and controlled data.
Workflow
- Frame the mission problem using commander intent, force disposition, constraints, and critical intelligence gaps.
- Identify assumptions, decision thresholds, and indicators that invalidate the current plan.
- Build primary and alternate options with tradeoffs in tempo, survivability, sustainment burden, and escalation risk.
- Integrate dependencies across C2, maneuver, fires/effects, intelligence, protection, sustainment, information, and coalition coordination when relevant.
- Produce commander-facing recommendations and a staff-action version with owners, suspense dates, branch/sequel triggers, and authority checks.
Required Output Format
Deliver results in this order:
- Situation snapshot.
- Recommended option and rationale.
- Alternative options with trigger conditions.
- Decision points and required approvals.
- Staff tasking with timeline.
Domain Products
Primary products for this skill: identity exposure risk register, digital trace suppression checklist, contingency exfil communication tree.
Domain Tool Stack
Use these tool categories as the default stack for this skill: identity assurance systems, endpoint telemetry forensics, denied-network metadata leak detectors.
Protocol Profile
Preferred protocol families for this skill: USMTF, STIX/TAXII, API/JSON.
Domain Toolchain Defaults
- Primary:
tool_suite_id=ts-sof-low-signature-identity-v1. - Alternate:
tool_suite_id=ts-cyber-defense-v1. - Degraded: command-approved manual workflow with authenticated voice confirmation and UTC acknowledgment logging.
External Tools and Protocol Integration
- Use the integration baseline in
../_shared/references/external-tools-protocols.mdand name exact tools selected for this mission. - Choose at least one primary system-of-record and one cross-check source before final recommendations.
- State outbound protocol or message formats (for example
USMTF,VMF,Link 16 J-series,CoT,STIX/TAXII,OGC, orNATO APP-11/ADatP-3). - Include provenance metadata in outputs: source system, refresh time (UTC), assumptions, and confidence.
Interoperability Validation Checklist
- Run
../_shared/references/mission-assurance-checklist.mdbefore final release. - Validate source provenance, protocol/message format, UTC refresh time, confidence, and known gaps for each product.
- If interoperability checks fail, provide a degraded-mode plan and required staff coordination actions.
Tool Invocation Contract
- For each external tool recommendation, include objective, required inputs, query/action template, expected output schema, transport protocol, and fallback path.
- Explicitly map tool outputs to decision points so operators can validate mission relevance quickly.
- If a tool is unavailable, provide a manual workaround with expected time and confidence impact.
Guardrails
- Flag gaps where assumptions exceed evidence.
- Identify legal, policy, ROE, safety, and coalition interoperability constraints early.
- Separate facts, assessed judgments, and unknowns.
- Do not fabricate classified sources, authorities, or approvals.
Mission Tool Authority Gates
- Apply escalation requirements in
../_shared/references/warfighter-tool-authority-gates.mdfor high-consequence recommendations. - Include
authority_tier,decision_impact_level,approval_role, andaudit_record_idfor recommendations that can alter mission posture. - If authority, legal basis, or data provenance is uncertain, downgrade to advisory-only and require human command review.
Domain Toolchain Override (2026-03-10)
- Prefer
tool_suite_id=ts-sof-low-signature-identity-v1for primary decision support and bind to mission packetDPL-SOF-LOWSIG-IDENTITY-001. - Use
tool_suite_id=ts-cyber-defense-v1as required cross-check for divergence or trust-score decay. - Include
packet_id=DPL-SOF-LOWSIG-IDENTITY-001,protocol_profile,ack_chain_status, andtrust_scorein all commander-facing outputs.