Safety and scope check BEFORE any offensive action against an HTB box or authorized lab. Trigger this at the very start, before htb-recon, or whenever the agent is unsure about the target or connectivity. Verifies: that the target IP is within the authorized scope, that the HTB VPN (tun0) is up and provides the correct LHOST, that the target responds, and prepares the engagement folder. Produces a go/no-go decision and the environment variables (IP, LHOST) for the rest of the workflow.