Read-only audit of observability on MikroTik RouterOS: logging only in memory, critical topics not logged, remote logging to a dead collector, NTP client off or clock wrong, open NTP server, permanent debug topics, e-mail without TLS or with a stored credential, evidence never handled, Netwatch actions, SNMP communities (default, unrestricted, write-enabled), trap protection and destinations, v1/v2c on untrusted networks. This skill should be used when assessing whether a RouterOS device would tell anyone that something happened, without changing configuration.