mirror of
https://github.com/CyberSecurityUP/NeuroSploit.git
synced 2026-09-29 12:31:43 +02:00
The existing voters answer "is this finding real?", which invites judging the whole narrative at once — and that is how a proven missing control got deleted for having an overstated headline. One lever, one verdict, observation gone. The Evidence Prosecutor has a narrower brief and four questions in order: what exactly was observed, which sentences go beyond that, what would have to be observed for the claimed impact to be factual, and — the one that decides retain-versus-reject — would anything security-relevant remain if the unsupported sentences were removed. It cannot pass sentence. There is no verdict field in its contract (a test asserts the prompt never offers one), and apply() can only narrow: the minimal supported statement replaces the mechanic, the asserted impact is demoted to potential with the conditions that would make it factual attached. Nothing it returns can raise a severity, add an impact, or drop a finding. A self-contradicting verdict — "nothing survives" alongside a minimal claim — is detected and the reading that keeps the observation wins: the claim is a concrete artifact, the boolean is an opinion about it. Findings from before the claim contract get a ledger reconstructed from what they recorded (structured evidence where present, quoted evidence lines otherwise), so the back catalogue is judged rather than silently skipped. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>